CVE-2024-0161: Input Validation
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0161?
CVE-2024-0161 is classified as a medium severity vulnerability due to the potential for local low privileged attackers to exploit it.
How do I fix CVE-2024-0161?
To fix CVE-2024-0161, update the firmware of affected Dell PowerEdge Servers and Precision Rack Servers to the latest version provided by Dell.
Who is vulnerable to CVE-2024-0161?
CVE-2024-0161 affects various models of Dell PowerEdge Servers and Precision Rack Servers prior to their respective firmware updates.
What does CVE-2024-0161 exploit?
CVE-2024-0161 exploits an improper verification of the SMM communication buffer, which could allow arbitrary writes to SMRAM.
Is CVE-2024-0161 easy to exploit?
CVE-2024-0161 requires local access by a low privileged attacker, making it less likely to be exploited remotely.