CVE-2024-42446: TOCTOU in SmmWhea
Published May 13, 2025
·Updated
APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.
Affected Software
2 affected components
APTIOV BIOS
AMI Aptio V>=5.0<5.039
Event History
May 13, 2025
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42446?
The severity of CVE-2024-42446 is considered high due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-42446?
To mitigate CVE-2024-42446, users should update their APTIOV BIOS to the latest version provided by the vendor.
3
Who is affected by CVE-2024-42446?
CVE-2024-42446 affects systems that use the APTIOV BIOS.
4
What type of vulnerability is CVE-2024-42446?
CVE-2024-42446 is a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability.
5
Can CVE-2024-42446 be exploited remotely?
CVE-2024-42446 requires local access to the affected system for exploitation.