PT-2022-11538 · Insyde · Insydeh2O Kernel

Published

2022-02-03

·

Updated

2022-04-18

·

CVE-2021-42059

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O Kernel 5.0 before 05.08.41 Insyde InsydeH2O Kernel 5.1 before 05.16.41 Insyde InsydeH2O Kernel 5.2 before 05.26.41 Insyde InsydeH2O Kernel 5.3 before 05.35.41 Insyde InsydeH2O Kernel 5.4 before 05.42.20
Description A stack-based buffer overflow in the UEFI DisplayTypeDxe DXE driver leads to arbitrary code execution. This issue allows a local root user to access the UEFI DXE driver and execute arbitrary code.
Recommendations For Insyde InsydeH2O Kernel 5.0 before 05.08.41, update to version 05.08.41 or later. For Insyde InsydeH2O Kernel 5.1 before 05.16.41, update to version 05.16.41 or later. For Insyde InsydeH2O Kernel 5.2 before 05.26.41, update to version 05.26.41 or later. For Insyde InsydeH2O Kernel 5.3 before 05.35.41, update to version 05.35.41 or later. For Insyde InsydeH2O Kernel 5.4 before 05.42.20, update to version 05.42.20 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42059

Affected Products

Insydeh2O Kernel