Buffer overflow in UEFI firmware and Intel Server D50FCP - CVE-2024-23980
Published: May 22, 2024
Vulnerability identifier: #VU89751
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23980
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in PlatformPfrDxe driver. A local administrator can trigger memory corruption and execute arbitrary code on the target system with elevated privileges.
Affected software
UEFI firmware
Intel Server D50FCP
Intel Server D50FCP
How to mitigate CVE-2024-23980
Install updates from vendor's website.