PT-2022-23005 · Insyde · Insydeh2O
Published
2022-11-21
·
Updated
2022-11-30
·
CVE-2022-35897
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Insyde InsydeH2O with kernel 5.0 through 5.5
Description
A stack buffer overflow issue leads to arbitrary code execution when specific UEFI variables are modified. Normally, these variables are locked at the OS level, requiring an attacker to make direct SPI modifications. If an attacker changes at least two out of three variables -
SecureBootEnforce, SecureBoot, RestoreBootSettings - it is possible to execute arbitrary code.Recommendations
For Insyde InsydeH2O with kernel 5.0 through 5.5, consider restricting access to the UEFI variables
SecureBootEnforce, SecureBoot, and RestoreBootSettings to prevent modification and minimize the risk of exploitation. As a temporary workaround, ensure these variables are properly secured at the OS level to prevent unauthorized changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insydeh2O