CVE-2020-5348

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
04/04/2020
Last modified:
06/04/2020

Description

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:latitude_7202_firmware:*:*:*:*:*:*:*:* a28 (excluding)
cpe:2.3:h:dell:latitude_7202:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools