Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-25078


A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.


Published

2024-05-15T14:15:08.250

Last Modified

2025-07-29T20:02:06.667

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-822

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System insyde kernel < 5.29.07 Yes
Operating System insyde kernel < 5.38.07 Yes
Operating System insyde kernel < 5.46.07 Yes
Operating System insyde kernel < 5.54.07 Yes
Operating System insyde kernel < 5.61.07 Yes

References