CVE-2020-5378: Use After Free
Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFIBOOTSERVICES structure to execute arbitrary code in System Management Mode (SMM).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5378 vulnerability?
CVE-2020-5378 is a UEFI BIOS Boot Services overwrite vulnerability in Dell G7 17 7790 BIOS versions prior to 1.13.2.
How can this vulnerability be exploited?
A local attacker with access to system memory can exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).
What is the severity of CVE-2020-5378?
The severity of CVE-2020-5378 vulnerability is high with a CVSS score of 6.8.
Which software versions are affected by CVE-2020-5378?
Dell G7 17 7790 BIOS versions prior to 1.13.2 are affected by CVE-2020-5378.
How can I fix CVE-2020-5378 vulnerability?
To fix CVE-2020-5378 vulnerability, update your Dell G7 17 7790 BIOS to version 1.13.2 or later.