PT-2025-16503 · Insyde · Insydeh2O

Published

2025-04-08

·

Updated

2025-04-16

·

CVE-2024-49200

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Insyde InsydeH2O versions 5.2 through 5.7
Description A potential memory corruption issue has been identified in AcpiS3SaveDxe and ChipsetSvcDxe. The root cause is the use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution.
Recommendations For kernel 5.2, update to Version 05.29.44. For kernel 5.3, update to Version 05.38.44. For kernel 5.4, update to Version 05.46.44. For kernel 5.5, update to Version 05.54.44. For kernel 5.6, update to Version 05.61.44. For kernel 5.7, update to Version 05.70.44.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14944
CVE-2024-49200

Affected Products

Insydeh2O