CVE-2024-33657

HIGH

AMI Aptio V 5.0-5.35 - Authenticated Arbitrary Code Execution and Denial of Service via SMM Vulnerability

Title source: llm
STIX 2.1

Description

This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 9.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
ami/aptio_v 5.0 - 5.36
Published Aug 21, 2024
Tracked Since Feb 18, 2026