CVE-2024-36354

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.
Configurations

No configuration.

History

06 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-06 18:15

Updated : 2025-09-06 18:15


NVD link : CVE-2024-36354

Mitre link : CVE-2024-36354

CVE.ORG link : CVE-2024-36354


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation