Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39283


An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.


Published

2023-11-02T22:15:09.070

Last Modified

2024-11-21T08:15:03.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application insyde insydeh2o ≤ 5.5 Yes
Application insyde insydeh2o 5.5.05.53.22 Yes
Application insyde insydeh2o 5.6 Yes
Application insyde insydeh2o 5.6.05.60.22 Yes

References