CVE-2023-22615
Published Apr 11, 2023
Last updated a year ago
Overview
- Description
- An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can pass an address in the RCX save state register that overlaps SMRAM, thereby coercing an IHISI subfunction handler to overwrite private SMRAM.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.4
- Impact score
- 5.8
- Exploitability score
- 2
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- CWE-787
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:insyde:insydeh2o:05.37.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCF923E3-CC99-454A-921F-50C29CAE4EDD" }, { "criteria": "cpe:2.3:a:insyde:insydeh2o:05.45.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D1DE977-6288-4AC8-8A07-1025422E94FF" }, { "criteria": "cpe:2.3:a:insyde:insydeh2o:05.53.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB625C43-BC20-42DF-991A-83BFF79B45AC" } ], "operator": "OR" } ] } ]