PT-2024-20729 · Insyde · Insydeh2O

Published

2024-05-15

·

Updated

2025-07-29

·

CVE-2024-25078

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O versions prior to kernel 5.2: IB19130163 in 05.29.07 Insyde InsydeH2O versions prior to kernel 5.3: IB19130163 in 05.38.07 Insyde InsydeH2O versions prior to kernel 5.4: IB19130163 in 05.46.07 Insyde InsydeH2O versions prior to kernel 5.5: IB19130163 in 05.54.07 Insyde InsydeH2O versions prior to kernel 5.6: IB19130163 in 05.61.07
Description A memory corruption vulnerability in StorageSecurityCommandDxe could lead to escalating privileges in SMM.
Recommendations For Insyde InsydeH2O versions prior to kernel 5.2: IB19130163 in 05.29.07, update to a version that includes the fix IB19130163 in 05.29.07 or later. For Insyde InsydeH2O versions prior to kernel 5.3: IB19130163 in 05.38.07, update to a version that includes the fix IB19130163 in 05.38.07 or later. For Insyde InsydeH2O versions prior to kernel 5.4: IB19130163 in 05.46.07, update to a version that includes the fix IB19130163 in 05.46.07 or later. For Insyde InsydeH2O versions prior to kernel 5.5: IB19130163 in 05.54.07, update to a version that includes the fix IB19130163 in 05.54.07 or later. For Insyde InsydeH2O versions prior to kernel 5.6: IB19130163 in 05.61.07, update to a version that includes the fix IB19130163 in 05.61.07 or later.

Fix

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2024-25078

Affected Products

Insydeh2O