Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/912156 | third party advisory us government resource |
https://www.blackhat.com/us-13/archives.html#Butterworth | |
https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-Slides.pdf | exploit |
https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-WP.pdf | exploit |
http://www.kb.cert.org/vuls/id/BLUU-99HSLA | us government resource |