VDB

CVE-2023-5058

CVE-2023-5058 PUBLISHED

BRLY-LOGOFAIL-2023-025 Low CVE-2023-5058 BINARLY efiXplorer team has discovered a memory contents leak / information disclosure vulnerability. Lack of synchronization between PaletteSize calculated from BitsPerPixel in BMP Image Header and PaletteIndex calculated from data in BMP Image allows OOB Read in Phoenix firmware.

EPSS 0.27% · 17.4th percentile

Risk Scores

EPSS Score
0.27%
17.4th percentile

Timeline

  • Dec 6, 2023 CVE Published
  • Dec 8, 2023 EPSS Score
  • Dec 11, 2023 PoC Published
  • Dec 31, 2023 PoC Published
  • Jan 7, 2024 EPSS Score
  • Feb 6, 2024 EPSS Score
  • Mar 6, 2024 EPSS Score
  • Apr 5, 2024 EPSS Score
  • May 5, 2024 EPSS Score
  • Jun 4, 2024 EPSS Score
  • Jul 4, 2024 EPSS Score
  • Aug 2, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›