CVE-2024-54084: SMM Arbitrary Write via TOCTOU Vulnerability
Published Mar 11, 2025
·Updated
APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.
Affected Software
2 affected components
APTIOV BIOS
AMI Aptio V>=5.0<5.038
Event History
Mar 11, 2025
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54084?
CVE-2024-54084 has a high severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-54084?
To mitigate CVE-2024-54084, it is recommended to update the APTIOV BIOS to the latest version provided by the vendor.
3
Who is affected by CVE-2024-54084?
CVE-2024-54084 affects systems utilizing APTIOV BIOS that are susceptible to TOCTOU race conditions.
4
What type of vulnerability is CVE-2024-54084?
CVE-2024-54084 is classified as a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
5
Can CVE-2024-54084 be exploited remotely?
CVE-2024-54084 requires local access to exploit, meaning it cannot be exploited remotely.