7.1
CVSSv3

CVE-2023-25600

Published: 03/08/2023 Updated: 08/08/2023
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.

Vulnerable Product Search on Vulmon Subscribe to Product

insyde insydecrpkg