Impact
An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value. This can result in a system crash or in the corruption of the BIOS firmware, compromising system integrity and availability. The vulnerability does not provide remote code execution or privilege escalation beyond the local administrator role.
Affected Systems
The flaw impacts ASUS FA507NU and ASUS FA507NV models running BIOS version 318.
Risk and Exploitability
The CVSS score of 6.8 places the issue in the "medium" severity range. The EPSS score of approximately 0.11% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. Given that the attack requires local privileged access, the likelihood of exploitation is moderate and primarily limited to environments where system administrators have direct control of the hardware. As such, timely remediation through a BIOS update is strongly recommended to mitigate the risk.
OpenCVE Enrichment