CVE-2020-5348: Use After Free
Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFIBOOTSERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFIBOOTSERVICES structure to execute arbitrary code in system management mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell Latitude 7202 Rugged Tablet BIOSto a version that resolves this vulnerability.Fixed in A28
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell Latitude 7202 Rugged Tablet BIOS vulnerability?
The vulnerability ID for this Dell Latitude 7202 Rugged Tablet BIOS vulnerability is CVE-2020-5348.
What is the severity of CVE-2020-5348?
The severity of CVE-2020-5348 is high (7.8).
What is the affected software for CVE-2020-5348?
The affected software for CVE-2020-5348 is Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28.
How can a local unauthenticated attacker exploit CVE-2020-5348?
A local unauthenticated attacker can exploit CVE-2020-5348 by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
How can I fix the vulnerability in Dell Latitude 7202 Rugged Tablet BIOS?
To fix the vulnerability in Dell Latitude 7202 Rugged Tablet BIOS, update to version A28 or later.