Database/Firmware, BMC & network fabric

UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at boot
CVE-2023-39538Firmware, BMC & network fabricLogoFAILcurated
Impact
Unrestricted upload of a crafted BMP logo parsed by the BIOS at boot; leads to code execution in DXE, before Secure Boot is enforced. Persistent, invisible to the OS
Who can reach it
Local write access to the ESP
What to do
BIOS/UEFI firmware update per platform — the slowest update in the stack, gated on the ODM shipping an AMI rebase. No dbx-style shortcut exists because the flaw is in the firmware, not a signed binary
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.