Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 &…
Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.
https://cwe.mitre.org/data/definitions/226.html →Open in CWE collection →An attacker examines a target system to find sensitive data that has been embedded within it. This information can reveal confidential contents, such as account numbers or individual keys/credentials that can be used as an intermediate step in a larger attack.
https://capec.mitre.org/data/definitions/37.html →Open in CAPEC collection →| Product | Vendor | Status |
|---|---|---|
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2 | Tracked | |
| edk2-tools | Tracked | |
| edk2-tools-doc | Tracked | |
| bios | * | Tracked |
| debian_linux | * | Tracked |