An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.
2023-08-03T15:15:19.340
2024-11-21T07:49:48.400
Modified
CVSSv3.1: 7.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | insyde | insydecrpkg | < 01.01.04.0016 | Yes |