Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22615


An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHISI subfunction handler to overwrite private SMRAM.


Published

2023-04-11T21:15:17.733

Last Modified

2025-02-11T21:15:10.803

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.4 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o 05.37.03 Yes
Application insyde insydeh2o 05.45.01 Yes
Application insyde insydeh2o 05.53.01 Yes

References