Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22613


An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.


Published

2023-04-11T22:15:07.660

Last Modified

2025-02-11T20:15:31.633

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o 05.27.37 Yes
Application insyde insydeh2o 05.36.37 Yes
Application insyde insydeh2o 05.44.45 Yes
Application insyde insydeh2o 05.52.45 Yes

References