Multiple Vendor BIOS SYSENTER Denial Of Service Vulnerability
BID:8277
Info
Multiple Vendor BIOS SYSENTER Denial Of Service Vulnerability
| Bugtraq ID: | 8277 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 24 2003 12:00AM |
| Updated: | Jul 24 2003 12:00AM |
| Credit: | Vulnerability reported by Michal Zalewski. |
| Vulnerable: |
Toshiba Satellite 1410-303 1.20 SystemSoft BIOS R1.04 Phoenix Technologies BIOS R0217U0 IBM ThinkPad X IZET9AWW 2.22 Dell Latitude CPx H* revision A09 Dell Latitude CPi A* revision A15 Compaq 686T2 8.22.1999 |
| Not Vulnerable: |
Dell OptiPlex GX150 revision A10 Dell Latitude C800 revision A17 Dell Latitude C640 revision A08 |
Discussion
Multiple Vendor BIOS SYSENTER Denial Of Service Vulnerability
It has been reported that under certain circumstances, it may be possible for local users to crash dual-boot systems. This issue is present due to the BIOS failing to reset certain Model-Specific Registers (MSRs) on reboot. This could leave the CPU in a potentially unstable state, in the event that SYSENTER is invoked by an operating system that does not support the instruction.
It has been reported that under certain circumstances, it may be possible for local users to crash dual-boot systems. This issue is present due to the BIOS failing to reset certain Model-Specific Registers (MSRs) on reboot. This could leave the CPU in a potentially unstable state, in the event that SYSENTER is invoked by an operating system that does not support the instruction.
Exploit / POC
Multiple Vendor BIOS SYSENTER Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor BIOS SYSENTER Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.