Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34325


DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the StorageSecurityCommandDxe driver could cause SMRAM corruption. This issue was discovered by Insyde engineering based on the general description provided by


Published

2022-11-14T23:15:11.223

Last Modified

2025-04-30T20:15:18.307

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-367
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o < 05.36.23 Yes
Application insyde insydeh2o < 05.27.23 Yes
Application insyde insydeh2o < 05.44.23 Yes
Application insyde insydeh2o < 05.52.23 Yes

References