CVE-2024-33657

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
21/08/2024
Last modified:
12/01/2026

Description

This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ami:aptio_v:*:*:*:*:*:*:*:* 5.0 (including) 5.36 (including)