CVE-2023-22613
11.04.2023, 22:15
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.Enginsight
Vendor | Product | Version |
---|---|---|
insyde | insydeh2o | 05.27.37 |
insyde | insydeh2o | 05.36.37 |
insyde | insydeh2o | 05.44.45 |
insyde | insydeh2o | 05.52.45 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References