CVE-2023-52710

HIGH

Huawei Matebook D16 BIOS v2.26 - Improper Check for Unusual or Exceptional Conditions in Communication Buffer

Title source: llm
STIX 2.1

Description

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap with the beginning SMRAM.This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-754
Status published
Products (1)
huawei/curiem-wfg9b_firmware ota-curiem-bios-2.29
Published May 28, 2024
Tracked Since Feb 18, 2026