An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.
References
Link | Resource |
---|---|
https://www.insyde.com/security-pledge | Vendor Advisory |
https://www.insyde.com/security-pledge/SA-2022039 | Vendor Advisory |
https://www.insyde.com/security-pledge | Vendor Advisory |
https://www.insyde.com/security-pledge/SA-2022039 | Vendor Advisory |
Configurations
History
25 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-121 |
21 Nov 2024, 07:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.insyde.com/security-pledge - Vendor Advisory | |
References | () https://www.insyde.com/security-pledge/SA-2022039 - Vendor Advisory |
30 Nov 2022, 15:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:* | |
CWE | CWE-787 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
References | (MISC) https://www.insyde.com/security-pledge/SA-2022039 - Vendor Advisory | |
References | (MISC) https://www.insyde.com/security-pledge - Vendor Advisory |
23 Nov 2022, 13:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-11-23 03:15
Updated : 2025-04-25 21:15
NVD link : CVE-2022-36337
Mitre link : CVE-2022-36337
CVE.ORG link : CVE-2022-36337
JSON object : View
Products Affected
insyde
- kernel