Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30772


Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address and size of data to write into the SMBIOS table, but manipulation of the address could be used by malware to overwrite SMRAM or OS kernel memory. This issue was discovered by Insyde engineering during a security review. This issue is fixed in: Kernel 5.0: 05.09.41 Kernel 5.1: 05.17.43 Kernel 5.2: 05.27.30 Kernel 5.3: 05.36.30 Kernel 5.4: 05.44.30 Kernel 5.5: 05.52.30 https://www.insyde.com/security-pledge/SA-2022065


Published

2022-11-15T21:15:36.967

Last Modified

2025-04-30T16:15:21.463

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System insyde kernel < 5.0.05.09.41 Yes
Operating System insyde kernel < 5.1.05.17.43 Yes
Operating System insyde kernel < 5.2.05.27.30 Yes
Operating System insyde kernel < 5.3.05.36.30 Yes
Operating System insyde kernel < 5.4.05.44.30 Yes
Operating System insyde kernel < 5.5.05.52.30 Yes

References