PT-2025-16503 · Insyde · Insydeh2O
Published
2025-04-08
·
Updated
2025-04-16
·
CVE-2024-49200
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Insyde InsydeH2O versions 5.2 through 5.7
Description
A potential memory corruption issue has been identified in AcpiS3SaveDxe and ChipsetSvcDxe. The root cause is the use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution.
Recommendations
For kernel 5.2, update to Version 05.29.44.
For kernel 5.3, update to Version 05.38.44.
For kernel 5.4, update to Version 05.46.44.
For kernel 5.5, update to Version 05.54.44.
For kernel 5.6, update to Version 05.61.44.
For kernel 5.7, update to Version 05.70.44.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insydeh2O