8.4
CVSSv3

CVE-2023-22615

Published: 11/04/2023 Updated: 14/08/2023
CVSS v3 Base Score: 8.4 | Impact Score: 5.8 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

An issue exists in IhisiSmm in Insyde InsydeH2O with kernel 5.0 up to and including 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHISI subfunction handler to overwrite private SMRAM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

insyde insydeh2o 05.37.03

insyde insydeh2o 05.45.01

insyde insydeh2o 05.53.01