CVE-2021-41839: Buffer Overflow
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-41839.
What is the severity of CVE-2021-41839?
The severity of CVE-2021-41839 is high with a score of 8.2.
What is the affected software for CVE-2021-41839?
The affected software for CVE-2021-41839 is InsydeH2O version 5.0 through 5.5.
What is the impact of exploiting CVE-2021-41839?
Exploiting CVE-2021-41839 could lead to escalating privileges and write fixed or predictable data to SMRAM.
Where can I find more information about CVE-2021-41839?
You can find more information about CVE-2021-41839 in the following references: [https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf), [https://security.netapp.com/advisory/ntap-20220217-0016/](https://security.netapp.com/advisory/ntap-20220217-0016/), [https://www.insyde.com/security-pledge](https://www.insyde.com/security-pledge).