NA

CVE-2022-36337

Published: 23/11/2022 Updated: 30/11/2022
CVSS v3 Base Score: 8.2 | Impact Score: 6 | Exploitability Score: 1.5
VMScore: 0

Vulnerability Summary

An issue exists in Insyde InsydeH2O with kernel 5.0 up to and including 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

insyde kernel