CVE-2022-35895
21.09.2022, 21:15
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input parameters for a software SMI routine, leading to memory corruption of arbitrary addresses including SMRAM, and possible arbitrary code execution.Enginsight
Vendor | Product | Version |
---|---|---|
insyde | insydeh2o | 5.0 ≤ 𝑥 < 05.09.37 |
insyde | insydeh2o | 5.1 ≤ 𝑥 < 05.17.37 |
insyde | insydeh2o | 5.2 ≤ 𝑥 < 05.27.29 |
insyde | insydeh2o | 5.3 ≤ 𝑥 < 05.36.29 |
insyde | insydeh2o | 5.4 ≤ 𝑥 < 05.44.29 |
insyde | insydeh2o | 5.5 ≤ 𝑥 < 05.52.29 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration