CVE-2020-5953: High severity Insyde InsydeH2O vulnerability
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFIRUNTIMESERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5953.
What software is affected by this vulnerability?
The affected software includes InsydeH2O UEFI Firmware versions 5.12.09.0074, 5.23.04.0045, 5.23.45.0023, 5.33.15.0034, 5.34.03.0029, and 5.42.03.0010.
What is the severity of CVE-2020-5953?
The severity of CVE-2020-5953 is high, with a CVSS score of 7.5.
How does this vulnerability work?
This vulnerability allows an attacker to execute arbitrary code in SMM (System Management Mode) by exploiting a vulnerability in the System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware.
Is there a fix available for this vulnerability?
Yes, it is recommended to update to the latest version of InsydeH2O UEFI Firmware to mitigate this vulnerability.