An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurityCommandDxe SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Se ha detectado un problema en InsydeH2O con el kernel versión 5.1 hasta 08-11-2021, versión 5.2 hasta 08-11-2021 y versión 5.3 hasta 08-11-2021. Una vulnerabilidad de corrupción de memoria de StorageSecurityCommandDxe SMM permite a un atacante escribir datos fijos o predecibles en la SMRAM. Una explotación de este problema podría conllevar a una escalada de privilegios en SMM
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | LOCAL |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a452540> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72efbdb0ac80> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f0c3beb280> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |