BRLY-2023-021
The Denial Of Service (DoS) vulnerability during PEI phase in EDK2 codebase.
CVE ID
CVE-2024-1298
Vendors Affected
EDK2
Products Affected
Intel NUC M15+2 more
Summary
The BINARLY efiXplorer team has identified a PEI-phase Denial of Service (DoS) vulnerability in the EDK2 codebase, which can be exploited by an attacker capable of modifying physical memory.
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks, and chart a path to post-quantum readiness.
Potential Impact
By modifying the physical memory from runtime, an attacker can trigger a division by 0 due to a UINT32 overflow. This vulnerability is exploitable on both client and server platforms where S3 sleep is activated.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2023-021
- Tianocore assigned CVE identifier: CVE-2024-1298
- CVSS v3.1: 6.0 Medium AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks with reachability and exploitation maturity scoring, and chart a measurable path to post-quantum readiness.