An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. Specially formatted buffer contents used for software SMI could cause SMRAM corruption, leading to escalation of privilege.
References
Link | Resource |
---|---|
https://www.insyde.com/security-pledge | Vendor Advisory |
https://www.insyde.com/security-pledge/SA-2023027 | Vendor Advisory |
Configurations
History
20 Apr 2023, 18:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-12 13:15
Updated : 2024-02-04 23:37
NVD link : CVE-2022-24350
Mitre link : CVE-2022-24350
CVE.ORG link : CVE-2022-24350
JSON object : View
Products Affected
insyde
- insydeh2o
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')