Improper access control in Intel SPI Flash - CVE-2017-5703

 

Improper access control in Intel SPI Flash - CVE-2017-5703

Published: April 10, 2018 / Updated: April 10, 2018


Vulnerability identifier: #VU11624
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5703
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to write arbitrary files and cause DoS condition on the target system.

The weakness exists due to improper access control. A local attacker can gain access to unsafe opcodes in SPI Flash, modify the behavior of the SPI Flash and cause the service to crash.

Affected software

Intel SPI Flash

How to mitigate CVE-2017-5703

Install update from vendor's website.


External References

Related Security Bulletins