An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Se ha descubierto un problema en AhciBusDxe en InsydeH2O con el kernel versión 5.1 hasta la versión 5.5. Una vulnerabilidad de corrupción de memoria en SMM permite a un atacante escribir datos fijos o predecibles en SMRAM. La explotación de este problema podría llevar a escalar privilegios a SMM
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | LOCAL |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72efbe6b1100> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f03a95dc40> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f059357500> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72f05a436940> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72effeddda40> | Application |
| insyde | insydeh2o | * | <built-in method update of dict object at 0x72effec6f580> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |