漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SMM Arbitrary Write via Dual-Controlled Pointers in CommandRcx1
Vulnerability Description
A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1 function. The write target is derived from an unvalidated UEFI NVRAM variable (SetupXtuBufferAddress), while the write content is read from an attacker-controlled pointer based on the RBX register. This dual-pointer dereference enables arbitrary memory writes within System Management RAM (SMRAM), leading to potential SMM privilege escalation and firmware compromise.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GIGABYTE Chipsets 安全漏洞
Vulnerability Description
GIGABYTE Chipsets是中国台湾技嘉(GIGABYTE)开源的一系列芯片组。 GIGABYTE Chipsets存在安全漏洞,该漏洞源于未验证指针,可能导致任意内存写入和权限提升。
CVSS Information
N/A
Vulnerability Type
N/A