An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.
References
Link | Resource |
---|---|
https://www.insyde.com/security-pledge | Not Applicable |
https://www.insyde.com/security-pledge/SA-2023055 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Nov 2023, 04:12
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:insyde:insydeh2o:5.6:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.5.05.53.22:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* cpe:2.3:a:insyde:insydeh2o:5.6.05.60.22:*:*:*:*:*:*:* |
|
First Time |
Insyde
Insyde insydeh2o |
|
References | (MISC) https://www.insyde.com/security-pledge - Not Applicable | |
References | (MISC) https://www.insyde.com/security-pledge/SA-2023055 - Vendor Advisory | |
CWE | CWE-787 |
02 Nov 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-02 22:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-39283
Mitre link : CVE-2023-39283
CVE.ORG link : CVE-2023-39283
JSON object : View
Products Affected
insyde
- insydeh2o
CWE
CWE-787
Out-of-bounds Write