There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) an...
There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) an...
공식 보안 권고 원문에서 현재 제품·에디션·설치 방식이 p13, p04, p11.a3l, p11.a4, p11.a4l, p12.b0l, p11-a4, p11.a1, p11.b3, p11.a2l, aap02sr, p21.a1, p21.a3, p11-a3, p11-b0l, p11.b0, p21.a0, p21.b0, p11.a3 기준의 대상인지 확인한 뒤 공급사 절차로 적용합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 n/a n/a, altos t110 f3 firmware, altos t110 f3 p13, p04, p11.a3l, p11.a4, p11.a4l, p12.b0l, p11-a4, p11.a1, p11.b3, p11.a2l, aap02sr, p21.a1, p21.a3, p11-a3, p11-b0l, p11.b0, p21.a0, p21.b0, p11.a3 기준을 충족하는지 확인합니다. 이어서 메모리 손상 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.