NA

CVE-2022-35893

Published: 23/09/2022 Updated: 08/08/2023
CVSS v3 Base Score: 8.2 | Impact Score: 6 | Exploitability Score: 1.5
VMScore: 0

Vulnerability Summary

An issue exists in Insyde InsydeH2O with kernel 5.0 up to and including 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an malicious user to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

insyde insydeh2o