メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。

文書番号: 000180645


DSA-2020-247: Dell Client Platform Security Update for UEFI BIOS RuntimeServices Overwrite Vulnerability

概要: Dell Inspiron 5675 contains remediation for a UEFI BIOS RuntimeServices Overwrite vulnerability that could be exploited by malicious users to compromise the affected system.

文書の内容


影響

Medium

詳細

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2020-26186 Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM).
 
6.8 CVSS:3.1:AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2020-26186 Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM).
 
6.8 CVSS:3.1:AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

Customers should use the latest releases available from Dell support when updating their systems.

Please visit the Drivers and Downloads site for updates on the applicable products. To learn more, visit the Dell Knowledge Base article Dell BIOS Updates, and download the update for your Dell computer.

Notes:
  • Prior to installing the update, please ensure Windows Updates are up to date.
  • The dates listed are estimated availability dates and are subject to change without notice.
  • Update versions in the table below are the first releases with the updates to address the security vulnerability. Releases at and above these versions will include the security updates.
  • Release dates below are in US format of MM/DD/YYYY.
  • Expected release dates are in the Month YYYY format.

Dell Client Consumer Products Affected

The following is a list of impacted products and expected release dates:
Product Update BIOS Version
(or greater)
Release Date (MM/DD/YYYY)
Expected Release (Month/YYYY)
Dell Inspiron 5675 1.4.1 11/18/2020
Customers should use the latest releases available from Dell support when updating their systems.

Please visit the Drivers and Downloads site for updates on the applicable products. To learn more, visit the Dell Knowledge Base article Dell BIOS Updates, and download the update for your Dell computer.

Notes:
  • Prior to installing the update, please ensure Windows Updates are up to date.
  • The dates listed are estimated availability dates and are subject to change without notice.
  • Update versions in the table below are the first releases with the updates to address the security vulnerability. Releases at and above these versions will include the security updates.
  • Release dates below are in US format of MM/DD/YYYY.
  • Expected release dates are in the Month YYYY format.

Dell Client Consumer Products Affected

The following is a list of impacted products and expected release dates:
Product Update BIOS Version
(or greater)
Release Date (MM/DD/YYYY)
Expected Release (Month/YYYY)
Dell Inspiron 5675 1.4.1 11/18/2020

回避策と緩和策

None

確認

Dell would like to thank yngweijw for reporting this vulnerability.
 

変更履歴

RevisionDateDescription
1.012/15/2020Initial Release

関連情報


文書のプロパティ


影響を受ける製品

Inspiron 5675, Product Security Information

最後に公開された日付

16 3月 2023

バージョン

2

文書の種類

Dell Security Advisory