Improper access control in Intel SPI Flash - CVE-2017-5703
Published: April 10, 2018 / Updated: April 10, 2018
Vulnerability identifier: #VU11624
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-5703
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Intel
Affected software:
Intel SPI Flash
Intel SPI Flash
Detailed vulnerability description
The vulnerability allows a local attacker to write arbitrary files and cause DoS condition on the target system.
The weakness exists due to improper access control. A local attacker can gain access to unsafe opcodes in SPI Flash, modify the behavior of the SPI Flash and cause the service to crash.
The weakness exists due to improper access control. A local attacker can gain access to unsafe opcodes in SPI Flash, modify the behavior of the SPI Flash and cause the service to crash.
How to mitigate CVE-2017-5703
Install update from vendor's website.