PT-2022-23314 · Insyde · Insydeh2O

Published

2022-11-23

·

Updated

2025-04-30

·

CVE-2022-36337

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O with kernel 5.0 through 5.5
Description A stack buffer overflow vulnerability in the MebxConfiguration driver can lead to arbitrary code execution. This issue occurs when a UEFI variable under the OS is read by BIOS code, causing the overflow.
Recommendations For Insyde InsydeH2O with kernel 5.0 through 5.5, consider disabling the MebxConfiguration driver as a temporary workaround until a patch is available. Restrict access to UEFI variables under the OS to minimize the risk of exploitation.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-36337

Affected Products

Insydeh2O