BRLY-2022-009
The arbitrary write vulnerability leads to arbitrary code execution during PEI phase on Intel platform.
CVE ID
CVE-2022-36372
Vendors Affected
AMI
Products Affected
[Intel Server Board M10JNP2SB](https://www.intel.com/content/www/us/en/download/19519/intel-server-board-m10jnp2sb-firmware-update-package.html)
Summary
BINARLY efiXplorer team has discovered a arbitrary write vulnerability on Intel platforms allowing a possible attacker to execute arbitrary code during PEI phase.
Image preview
Potential Impact
A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing memory isolation and confidential computing boundaries. Additionally, an attacker can build a payload which can be injected into the SMRAM memory.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2022-009
- Intel PSIRT assigned CVE identifier: CVE-2022-36372
- AMI PSIRT assigned CVE identifier: CVE-2022-40262
- CERT/CC assigned case number: VU#158026
- FwHunt rule: BRLY-2022-009
- CVSS v3.1: 8.2 High AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Image preview
See if you are impacted now with our Firmware Vulnerability Scanner
Find Vulnerabilities, Generate SBOMs & CBOMs