Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-22613

Опубликовано: 11 апр. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:insyde:insydeh2o:05.27.37:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:05.36.37:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:05.44.45:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:05.52.45:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00085
Низкий

8.8 High

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 8.8
github
почти 3 года назад

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

EPSS

Процентиль: 25%
0.00085
Низкий

8.8 High

CVSS3

Дефекты

CWE-787
CWE-787