DSA-2020-073: Dell Latitude 7202 Rugged Tablet Use After Free Vulnerability

Resumen: Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode. ...

Este artículo se aplica a: Este artículo no se aplica a: Este artículo no está vinculado a ningún producto específico. En este artículo no se identifican todas las versiones de los productos.

Impacto

Medium

Detalles

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
CVSS Base Score: 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
CVSS Base Score: 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Dell Technologies recomienda que todos los clientes tengan en cuenta la puntuación base CVSS y las puntuaciones temporales o de entorno relevantes que puedan afectar a la posible gravedad asociada a una determinada vulnerabilidad de seguridad.

Productos afectados y corrección

Affected products:

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28

Refer to the table below for the Dell Client BIOS release containing a resolution to this vulnerability.

Remediation:

Please visit Dell’s Drivers and Downloads site for updates on the applicable products. To learn more, visit the Dell Knowledge Base article Dell BIOS Updates and download the update for your Dell computer.

Customers may use one of the Dell notification solutions to be notified of and automatically download driver, BIOS and firmware updates once available.

 

Product

Update BIOS Version
(or greater)

Release Date (MM/DD/YYYY)
Expected Release ( Month /YYYY)

Dell Latitude 7202 Rugged Tablet

A28

March 2020

Affected products:

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28

Refer to the table below for the Dell Client BIOS release containing a resolution to this vulnerability.

Remediation:

Please visit Dell’s Drivers and Downloads site for updates on the applicable products. To learn more, visit the Dell Knowledge Base article Dell BIOS Updates and download the update for your Dell computer.

Customers may use one of the Dell notification solutions to be notified of and automatically download driver, BIOS and firmware updates once available.

 

Product

Update BIOS Version
(or greater)

Release Date (MM/DD/YYYY)
Expected Release ( Month /YYYY)

Dell Latitude 7202 Rugged Tablet

A28

March 2020

Agradecimientos

Dell would like to thank yngweijw for reporting this vulnerability.

Información relacionada

Productos afectados

Latitude 7202 Rugged Tablet

Productos

Tablets, Latitude Tablets
Propiedades del artículo
Número de artículo: 000128252
Tipo de artículo: Dell Security Advisory
Última modificación: 09 dic 2020
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.