BRLY-2022-015
The arbitrary code execution in DXE driver.
CVE ID
CVE-2022-34345
Vendors Affected
AMI
Products Affected
Intel NUC M15 BCTGL357 v0072 (Latest)
Summary
BINARLY efiXplorer team has discovered the ability of arbitrary code execution in DXE driver.
Image preview
Potential Impact
An attacker with physical access can exploit this vulnerability to execute arbitrary code during DXE phase. A malicious code installed as a result of vulnerability exploitation in DXE driver could survive across an operating system (OS) boot process and runtime.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2022-015
- Intel PSIRT assigned CVE identifier: CVE-2022-34345
- AMI PSIRT assigned CVE identifier: CVE-2022-2154
- CERT/CC assigned case number: VU#158026
- FwHunt rule: BRLY-2022-015
- CVSS v3.1: 7.2 High AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Image preview
See if you are impacted now with our Firmware Vulnerability Scanner
Find Vulnerabilities, Generate SBOMs & CBOMs