Stack overflow vulnerability in Aspire E5-475G 's BIOS firmware, in the FpGui module, a second call to GetVariable services allows local attackers to execute arbitrary code in the UEFI DXE phase and gain escalated privileges.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://acer.com/ | not applicable |
https://github.com/10TG/vulnerabilities/blob/main/Acer/CVE-2022-40080/CVE-2022-40080.md | third party advisory exploit |