CVE-2021-41840: High severity Insyde InsydeH2O vulnerability
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41840?
CVE-2021-41840 is a vulnerability discovered in NvmExpressDxe in the Insyde InsydeH2O kernel, allowing an attacker to access System Management Mode and execute arbitrary code.
What is the severity of CVE-2021-41840?
The severity of CVE-2021-41840 is high with a score of 8.2.
Which software versions are affected by CVE-2021-41840?
Insyde InsydeH2O versions between 5.2 and 5.23.35, between 5.3 and 5.32.35, and between 5.4 and 5.40.35 are affected by CVE-2021-41840.
How can an attacker exploit CVE-2021-41840?
An attacker can exploit CVE-2021-41840 by leveraging an SMM callout in NvmExpressDxe to access System Management Mode and execute arbitrary code.
Are there any patches or fixes available for CVE-2021-41840?
Please refer to the vulnerability references for information on available patches or fixes for CVE-2021-41840.