First published: Wed Nov 03 2021(Updated: )
An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde Insydeh2o Uefi Bios | <05.32.30.0001 | |
Intel Ice Lake | ||
Insyde Insydeh2o Uefi Bios | <05.41.35.0001 | |
Intel Tiger Lake | ||
Insyde Insydeh2o Uefi Bios | <05.42.11.0026 | |
Intel Whitley-sp | ||
Insyde Insydeh2o Uefi Bios | <05.04.21.0068 | |
Intel Grantley-ep | ||
Insyde Insydeh2o Uefi Bios | <05.42.09.0003 | |
Intel Elkhart Lake | ||
Insyde Insydeh2o Uefi Bios | <05.21.51.0040 | |
Intel Purley-ep Refresh Neon City | ||
Insyde Insydeh2o Uefi Bios | <05.34.09.0030 | |
Intel Comet Lake Rvp | ||
Intel Comet Lake Rvp | ||
Insyde Insydeh2o Uefi Bios | <05.32.47.0001 | |
Intel Comet Lake | ||
Insyde Insydeh2o Uefi Bios | <05.23.45.0023 | |
Intel Whiskey Lake Rvp | ||
Intel Whiskey Lake Rvp | ||
Insyde Insydeh2o Uefi Bios | <05.21.43.0001 | |
Intel Whiskey Lake | ||
Insyde Insydeh2o Uefi Bios | <05.23.04.0045 | |
Intel Mehlow | ||
Intel Mehlow-r | ||
Intel Mehlow-r | ||
Intel Mehlow | ||
Intel Coffee Lake | ||
Intel Cannon Lake | ||
Insyde Insydeh2o Uefi Bios | <05.11.26.0015 | |
Intel Kaby Lake Mrd | ||
Insyde Insydeh2o Uefi Bios | <05.12.09.0075 | |
Intel Greenlow | ||
Intel Greenlow-r | ||
Intel Greenlow | ||
Intel Greenlow-r | ||
Insyde Insydeh2o Uefi Bios | <05.10.48.0001 | |
Intel Kaby Lake | ||
Insyde Insydeh2o Uefi Bios | <05.05.39.0001 | |
Intel Skylake Mrd | ||
Insyde Insydeh2o Uefi Bios | <05.04.15.0001 | |
Intel Skylake | ||
Insyde Insydeh2o Uefi Bios | <05.23.27.0001 | |
Intel Coffee Lake | ||
Intel Whiskey Lake |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5955.
CVE-2020-5955 has a severity rating of 9.8 (critical).
The affected software is Insyde Insydeh2o Uefi Bios versions up to 05.32.30.0001 and up to 05.41.35.0001.
An attacker can exploit this vulnerability by calling Int15MicrocodeSmm to escalate privileges on Intel client chipsets.
No, Intel Ice Lake and Intel Tiger Lake are not vulnerable to CVE-2020-5955.