CVE-2024-36877
HIGH EPSS 47.8%
Published Aug 12, 20241y ago · Modified Jun 17, 20262w ago
8.2 CVSS 3.1
Published Aug 12, 2024 1y ago
Last Modified Jun 17, 2026 2w ago
Description
Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI 0xE3. Motherboard's with the following chipsets are affected: Intel 300, Intel 400, Intel 500, Intel 600, Intel 700, AMD 300, AMD 400, AMD 500, AMD 600 and AMD 700.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
47.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-123
References 2
- csr.msi.com https://csr.msi.com/global/product-security-advisories
- jjensn.com https://jjensn.com/at-home-in-your-firmware/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.