CVE-2022-24420: Buffer Overflow
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24420?
CVE-2022-24420 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2022-24420?
To mitigate CVE-2022-24420, update the affected Dell firmware to the latest version released by Dell.
What types of devices are affected by CVE-2022-24420?
CVE-2022-24420 affects multiple Dell products, including various models of Alienware, Inspiron, and Vostro series firmware.
Can a remote attacker exploit CVE-2022-24420?
CVE-2022-24420 requires local authenticated access, meaning a remote attacker cannot exploit this vulnerability directly.
What is the nature of the vulnerability in CVE-2022-24420?
CVE-2022-24420 is caused by improper input validation in Dell BIOS, allowing for potential arbitrary code execution within SMM.