CVE-2024-25078
15.05.2024, 14:15
A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.Enginsight
Vendor | Product | Version |
---|---|---|
insyde | kernel | 5.2 ≤ 𝑥 < 5.29.07 |
insyde | kernel | 5.3 ≤ 𝑥 < 5.38.07 |
insyde | kernel | 5.4 ≤ 𝑥 < 5.46.07 |
insyde | kernel | 5.5 ≤ 𝑥 < 5.54.07 |
insyde | kernel | 5.6 ≤ 𝑥 < 5.61.07 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration