CVE-2021-38578: Critical severity tianocore edk ii vulnerability
A flaw was found in edk2. A integer underflow in the SmmEntryPoint function leads to a write into the SMM region allowing a local attacker with administration privileges on the system to execute code within the SMM privileged context. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38578?
CVE-2021-38578 is a vulnerability in edk2 that allows a local attacker with administration privileges to execute code within the system management mode (SMM) context.
What is the severity of CVE-2021-38578?
CVE-2021-38578 has a severity score of 9.8 (Critical).
How does CVE-2021-38578 occur?
CVE-2021-38578 occurs due to an integer underflow in the SmmEntryPoint function in edk2, leading to a write into the SMM region.
Who is affected by CVE-2021-38578?
CVE-2021-38578 affects systems running edk2 with the specified versions and installations of Tianocore Edk2 and Insyde Kernel.
How can I fix CVE-2021-38578?
To fix CVE-2021-38578, update the affected software to the specified versions provided by the vendor.