An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
2023-04-11T22:15:07.660
2025-02-11T20:15:31.633
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | insyde | insydeh2o | 05.27.37 | Yes |
Application | insyde | insydeh2o | 05.36.37 | Yes |
Application | insyde | insydeh2o | 05.44.45 | Yes |
Application | insyde | insydeh2o | 05.52.45 | Yes |