Vulnerabilities > CVE-2022-26860 - Out-of-bounds Write vulnerability in Dell products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
dell
CWE-787

Summary

Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM.

Vulnerable Configurations

Part Description Count
OS
Dell
787
Hardware
Dell
399

Common Weakness Enumeration (CWE)