Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.