PT-2022-11538 · Insyde · Insydeh2O Kernel
Published
2022-02-03
·
Updated
2022-04-18
·
CVE-2021-42059
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Insyde InsydeH2O Kernel 5.0 before 05.08.41
Insyde InsydeH2O Kernel 5.1 before 05.16.41
Insyde InsydeH2O Kernel 5.2 before 05.26.41
Insyde InsydeH2O Kernel 5.3 before 05.35.41
Insyde InsydeH2O Kernel 5.4 before 05.42.20
Description
A stack-based buffer overflow in the UEFI DisplayTypeDxe DXE driver leads to arbitrary code execution. This issue allows a local root user to access the UEFI DXE driver and execute arbitrary code.
Recommendations
For Insyde InsydeH2O Kernel 5.0 before 05.08.41, update to version 05.08.41 or later.
For Insyde InsydeH2O Kernel 5.1 before 05.16.41, update to version 05.16.41 or later.
For Insyde InsydeH2O Kernel 5.2 before 05.26.41, update to version 05.26.41 or later.
For Insyde InsydeH2O Kernel 5.3 before 05.35.41, update to version 05.35.41 or later.
For Insyde InsydeH2O Kernel 5.4 before 05.42.20, update to version 05.42.20 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insydeh2O Kernel