First published: Tue May 28 2024(Updated: )
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Huawei Curiem-wfg9b | =ota-curiem-bios-2.29 | |
Huawei Curiem-wfg9b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52547 is considered to have a high severity due to potential data corruption and code execution risks.
To address CVE-2023-52547, updating the BIOS to the latest version provided by Huawei is recommended.
CVE-2023-52547 is a memory corruption vulnerability specifically located in the SMI Handler of the HddPassword SMM Module.
CVE-2023-52547 primarily affects users of the Huawei Matebook D16 with the specified BIOS version.
An attacker exploiting CVE-2023-52547 could potentially corrupt data structures and execute unauthorized code in the system management mode.