An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
References
Link | Resource |
---|---|
https://www.insyde.com/security-pledge/SA-2022035 | Vendor Advisory |
https://www.insyde.com/security-pledge | Vendor Advisory |
https://binarly.io/advisories/BRLY-2022-026/index.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Information
Published : 2022-09-23 12:15
Updated : 2022-09-28 09:06
NVD link : CVE-2022-35893
Mitre link : CVE-2022-35893
JSON object : View
CWE
Products Affected
insyde
- insydeh2o