Executive brief
The BIOS firmware in ASUS FA507NU and FA507NV laptops contains an out-of-bounds write vulnerability in the SmiFlash SMM (System Management Mode) module. A local administrator can exploit this via a crafted SMI request to crash the system or corrupt the BIOS, disrupting business operations and potentially requiring hardware service intervention.
Technical details
The vulnerability is an out-of-bounds write in the SmiFlash SMM module triggered by a crafted software SMI (SW SMI) request containing an oversized length value. It requires local administrator privileges to exploit. An attacker with admin access can trigger a system crash (BSOD) or BIOS corruption, leading to potential data loss or inability to boot the system. The vendor has released security updates through the ASUS Security Advisory to address this issue.
Affected products
- ASUS FA507NU BIOS
- ASUS FA507NV BIOS
Timeline
- 2026-08-27: disclosed