BRLY-2022-014
Arbitrary write vulnerability in PEI module leads to arbitrary code execution during PEI phase.
CVE ID
CVE-2022-32579
Vendors Affected
AMI
Products Affected
Intel NUC M15 BCTGL357 v0072 (Latest)
Summary
BINARLY efiXplorer team has discovered a arbitrary write vulnerability in PEI module allowing a possible attacker to execute arbitrary code during PEI phase.
Image preview
Potential Impact
A potential attacker can write one byte at an arbitrary address at the time of the PEI phase (only during S3 resume boot mode) and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing memory isolation and confidential computing boundaries. Additionally, an attacker can build a payload which can be injected into the SMRAM memory.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2022-014
- Intel PSIRT assigned CVE identifier: CVE-2022-32579
- AMI PSIRT assigned CVE identifier: CVE-2022-40246
- CVSS v3.1: 7.2 High AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- FwHunt rule: BRLY-2022-014
- CERT/CC assigned case number: VU#158026
Image preview
See if you are impacted now with our Firmware Vulnerability Scanner
Find Vulnerabilities, Generate SBOMs & CBOMs