PT-2023-18586 · Insyde · Insydeh2O

Jeremy Boone

+1

·

Published

2023-04-11

·

Updated

2025-02-11

·

CVE-2023-22613

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O with kernel versions 5.0 through 5.5
Description An issue was discovered in IhisiSmm that allows writing to an attacker-controlled address. This can be achieved by invoking an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
Recommendations For versions 5.0 through 5.5, consider disabling the SMI handler invocation with a malformed pointer in RCX to minimize the risk of SMM memory corruption until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-22613

Affected Products

Insydeh2O