PT-2022-23005 · Insyde · Insydeh2O

Published

2022-11-21

·

Updated

2022-11-30

·

CVE-2022-35897

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O with kernel 5.0 through 5.5
Description A stack buffer overflow issue leads to arbitrary code execution when specific UEFI variables are modified. Normally, these variables are locked at the OS level, requiring an attacker to make direct SPI modifications. If an attacker changes at least two out of three variables - SecureBootEnforce, SecureBoot, RestoreBootSettings - it is possible to execute arbitrary code.
Recommendations For Insyde InsydeH2O with kernel 5.0 through 5.5, consider restricting access to the UEFI variables SecureBootEnforce, SecureBoot, and RestoreBootSettings to prevent modification and minimize the risk of exploitation. As a temporary workaround, ensure these variables are properly secured at the OS level to prevent unauthorized changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-35897

Affected Products

Insydeh2O