DSA-2020-073: Dell Latitude 7202 Rugged Tablet Use After Free Vulnerability

Riepilogo: Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode. ...

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

Medium

Dettagli

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
CVSS Base Score: 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
CVSS Base Score: 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Affected products:

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28

Refer to the table below for the Dell Client BIOS release containing a resolution to this vulnerability.

Remediation:

Please visit Dell’s Drivers and Downloads site for updates on the applicable products. To learn more, visit the Dell Knowledge Base article Dell BIOS Updates and download the update for your Dell computer.

Customers may use one of the Dell notification solutions to be notified of and automatically download driver, BIOS and firmware updates once available.

 

Product

Update BIOS Version
(or greater)

Release Date (MM/DD/YYYY)
Expected Release ( Month /YYYY)

Dell Latitude 7202 Rugged Tablet

A28

March 2020

Affected products:

Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28

Refer to the table below for the Dell Client BIOS release containing a resolution to this vulnerability.

Remediation:

Please visit Dell’s Drivers and Downloads site for updates on the applicable products. To learn more, visit the Dell Knowledge Base article Dell BIOS Updates and download the update for your Dell computer.

Customers may use one of the Dell notification solutions to be notified of and automatically download driver, BIOS and firmware updates once available.

 

Product

Update BIOS Version
(or greater)

Release Date (MM/DD/YYYY)
Expected Release ( Month /YYYY)

Dell Latitude 7202 Rugged Tablet

A28

March 2020

Ringraziamenti

Dell would like to thank yngweijw for reporting this vulnerability.

Informazioni correlate

Prodotti interessati

Latitude 7202 Rugged Tablet

Prodotti

Tablets, Latitude Tablets
Proprietà dell'articolo
Numero articolo: 000128252
Tipo di articolo: Dell Security Advisory
Ultima modifica: 09 dic 2020
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.