PT-2017-17801 · Arm · Arm Trusted Firmware

CVE-2017-7563

·

Publicado

2017-06-07

·

Atualizado

2026-06-08

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ARM Trusted Firmware version 1.3
Description The issue in ARM Trusted Firmware allows attackers to bypass the MT EXECUTE NEVER protection mechanism because RO memory is always executable at AArch64 Secure EL1. This is due to an inconsistency in the number of execute-never bits.
Recommendations For ARM Trusted Firmware version 1.3, consider disabling or restricting access to the execute-never bits mechanism as a temporary workaround until a patch is available.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7563

Produtos afetados

Arm Trusted Firmware