An issue was discovered in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 before 05.14.28, Kernel 5.2 before 05.24.28, and Kernel 5.3 before 05.32.25. An SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
Se ha descubierto un problema en StorageSecurityCommandDxe en InsydeH2O con Kernel versión 5.1 antes de 05.14.28, Kernel versión 5.2 antes de 05.24.28 y Kernel versión 5.3 antes de 05.32.25. Una vulnerabilidad de llamada SMM permite a un atacante secuestrar el flujo de ejecución del código que se ejecuta en el modo de gestión del sistema. La explotación de este problema podría conducir a la escalada de privilegios al SMM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:L/Au:N/C:P/I:P/A:P
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f03a95c380> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a4edf80> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a4ee000> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |