An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The FjGabiFlashCoreAbstractionSmm driver registers a Software System Management Interrupt (SWSMI) handler that is not sufficiently validated to ensure that the CommBuffer (or any other communication buffer's nested contents) are not pointing to SMRAM contents. A potential attacker can therefore write fixed data to SMRAM, which could lead to data corruption inside this memory (e.g., change the SMI handler's code or modify SMRAM map structures to break input pointer validation for other SMI handlers). Thus, the attacker could elevate privileges from ring 0 to ring -2 and execute arbitrary code in SMM.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fujitsu
Subscribe
|
Lifebook A3510
Subscribe
Lifebook A3510 Firmware
Subscribe
Lifebook E449
Subscribe
Lifebook E449 Firmware
Subscribe
Lifebook E459
Subscribe
Lifebook E459 Firmware
Subscribe
Lifebook E5510
Subscribe
Lifebook E5510 Firmware
Subscribe
Lifebook U7310
Subscribe
Lifebook U7310 Firmware
Subscribe
Lifebook U7311
Subscribe
Lifebook U7311 Firmware
Subscribe
Lifebook U7410
Subscribe
Lifebook U7410 Firmware
Subscribe
Lifebook U7411
Subscribe
Lifebook U7411 Firmware
Subscribe
Lifebook U7510
Subscribe
Lifebook U7510 Firmware
Subscribe
Lifebook U7511
Subscribe
Lifebook U7511 Firmware
Subscribe
Lifebook U9310
Subscribe
Lifebook U9310 Firmware
Subscribe
Lifebook U9311
Subscribe
Lifebook U9311 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33244 | An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The FjGabiFlashCoreAbstractionSmm driver registers a Software System Management Interrupt (SWSMI) handler that is not sufficiently validated to ensure that the CommBuffer (or any other communication buffer's nested contents) are not pointing to SMRAM contents. A potential attacker can therefore write fixed data to SMRAM, which could lead to data corruption inside this memory (e.g., change the SMI handler's code or modify SMRAM map structures to break input pointer validation for other SMI handlers). Thus, the attacker could elevate privileges from ring 0 to ring -2 and execute arbitrary code in SMM. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T19:13:03.588Z
Reserved: 2022-04-08T00:00:00.000Z
Link: CVE-2022-28806
No data.
Status : Modified
Published: 2022-05-04T15:15:13.083
Modified: 2025-11-04T20:16:04.443
Link: CVE-2022-28806
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD