7.8
CVSSv3

CVE-2022-28806

Published: 04/05/2022 Updated: 18/05/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The FjGabiFlashCoreAbstractionSmm driver registers a Software System Management Interrupt (SWSMI) handler that is not sufficiently validated to ensure that the CommBuffer (or any other communication buffer's nested contents) are not pointing to SMRAM contents. A potential attacker can therefore write fixed data to SMRAM, which could lead to data corruption inside this memory (e.g., change the SMI handler's code or modify SMRAM map structures to break input pointer validation for other SMI handlers). Thus, the attacker could elevate privileges from ring 0 to ring -2 and execute arbitrary code in SMM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fujitsu lifebook_a3510_firmware

fujitsu lifebook_u9310_firmware

fujitsu lifebook_u7511_firmware

fujitsu lifebook_u7411_firmware

fujitsu lifebook_u7311_firmware

fujitsu lifebook_u9311_firmware

fujitsu lifebook_e5510_firmware

fujitsu lifebook_u7510_firmware

fujitsu lifebook_u7410_firmware

fujitsu lifebook_u7310_firmware

fujitsu lifebook_e459_firmware

fujitsu lifebook_e449_firmware