CVE-2021-46772

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
13/08/2024
Last modified:
15/04/2026

Description

Insufficient input validation in the ABL may allow a privileged<br /> attacker with access to the BIOS menu or UEFI shell to tamper with the<br /> structure headers in SPI ROM causing an out of bounds memory read and write,<br /> potentially resulting in memory corruption or denial of service.