First published: Tue May 28 2024(Updated: )
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker to corrupt arbitrary SMRAM memory and, in turn, lead to code execution in SMM
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Huawei Curiem-wfg9b | =ota-curiem-b-bios-2.28 | |
Huawei Curiem-wfg9b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52548 is classified as a severe vulnerability due to its potential for arbitrary memory corruption and code execution.
To address CVE-2023-52548, users should update the affected Huawei Matebook D16 BIOS to the latest version, specifically ota-curiem-b-bios-2.28.
CVE-2023-52548 specifically affects the Huawei Matebook D16 model CREM-WXX9 with BIOS version v2.26.
Exploitation of CVE-2023-52548 could allow a malicious OS attacker to corrupt SMRAM memory, leading to unauthorized code execution.
As of now, there is no indication that CVE-2023-52548 is being actively exploited in the wild.