ARM TrustZone Technology Vulnerability: Unauthorized Write Access to Kernel Code and Data

ARM TrustZone Technology Vulnerability: Unauthorized Write Access to Kernel Code and Data

CVE-2021-34387 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.

Learn more about our Web Application Penetration Testing UK.