Description
A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the contents at RBX match certain expected values (e.g., '$DB$' or '2DB$'), the function performs arbitrary writes to System Management RAM (SMRAM), leading to potential privilege escalation to System Management Mode (SMM) and persistent firmware compromise.
Problem types
CWE-822 Untrusted Pointer Dereference
Product status
References
www.kb.cert.org/vuls/id/746790
www.gigabyte.com/Support/Security
www.binarly.io/advisories/brly-dva-2025-008