GPU VulnDB

Database/Firmware, BMC & network fabric

UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at boot

CVE-2023-39538Firmware, BMC & network fabricLogoFAILcurated

Impact

Unrestricted upload of a crafted BMP logo parsed by the BIOS at boot; leads to code execution in DXE, before Secure Boot is enforced. Persistent, invisible to the OS

Who can reach it

Local write access to the ESP

What to do

BIOS/UEFI firmware update per platform — the slowest update in the stack, gated on the ODM shipping an AMI rebase. No dbx-style shortcut exists because the flaw is in the firmware, not a signed binary

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.