← Back

CVE-2023-22615

nvd nist
Published: Apr 11, 2023Modified: Feb 11, 2025

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Exploitability: 2.0 / Impact: 5.8
Source: NVD

Description

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHISI subfunction handler to overwrite private SMRAM.

Affected (3)

Products: Insyde: Insydeh2o
1 product
Insydeh2o
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Insyde
Version 05.37.03
Version 05.45.01
Version 05.53.01

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.