A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an...
High severity
Unreviewed
Published
Aug 13, 2024
to the GitHub Advisory Database
•
Updated Oct 2, 2024
Description
Published by the National Vulnerability Database
Aug 13, 2024
Published to the GitHub Advisory Database
Aug 13, 2024
Last updated
Oct 2, 2024
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrary code execution.
References