Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mc9-qpvm-p7p4

Опубликовано: 15 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the command buffer contents with DMA after the input parameters have been checked but before they are used, the IHISI SMM code may be convinced to modify SMRAM or OS, leading to possible data corruption or escalation of privileges.

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the command buffer contents with DMA after the input parameters have been checked but before they are used, the IHISI SMM code may be convinced to modify SMRAM or OS, leading to possible data corruption or escalation of privileges.

EPSS

Процентиль: 15%
0.00049
Низкий

7 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7
nvd
почти 3 года назад

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the command buffer contents with DMA after the input parameters have been checked but before they are used, the IHISI SMM code may be convinced to modify SMRAM or OS, leading to possible data corruption or escalation of privileges.

EPSS

Процентиль: 15%
0.00049
Низкий

7 High

CVSS3

Дефекты

CWE-367