First published: Tue May 28 2024(Updated: )
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap with the beginning SMRAM.This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Huawei Curiem-wfg9b | =ota-curiem-bios-2.29 | |
Huawei Curiem-wfg9b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52710 has a high severity due to its potential to allow malicious OS attackers to corrupt sensitive data structures.
To fix CVE-2023-52710, update the BIOS to version 2.29 or later for Huawei Matebook D16.
CVE-2023-52710 affects the Huawei Matebook D16, particularly models with BIOS version 2.26.
The potential impacts of CVE-2023-52710 include unauthorized data access and system instability due to data structure corruption.
Currently, there is no confirmed workaround for CVE-2023-52710, and it is recommended to update the BIOS as soon as possible.