CVE-2020-14032: Critical severity asrock box-r1000 firmware vulnerability
Published Jul 23, 2021
·Updated
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
Affected Software
1 affected component
ASRock Box-r1000 Firmware<1.40
Event History
Jul 23, 2021
CVE Published
via MITRE·10:13 AM
Data Sourced
via MITRE·10:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-14032?
CVE-2020-14032 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2020-14032?
To mitigate CVE-2020-14032, update the ASRock Box-R1000 firmware to version 1.40 or later.
3
What type of vulnerability is CVE-2020-14032?
CVE-2020-14032 is a privilege escalation vulnerability that allows code execution in the System Management Mode (SMM).
4
Who is affected by CVE-2020-14032?
The vulnerability affects users of the ASRock Box-R1000 firmware versions prior to 1.40.
5
Can CVE-2020-14032 be exploited remotely?
CVE-2020-14032 may potentially be exploited locally by an attacker with the ability to execute code.