First published: Thu Feb 03 2022(Updated: )
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.2<5.23.35 | |
Insyde InsydeH2O | >=5.3<5.32.35 | |
Insyde InsydeH2O | >=5.4<5.40.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41840 is a vulnerability discovered in NvmExpressDxe in the Insyde InsydeH2O kernel, allowing an attacker to access System Management Mode and execute arbitrary code.
The severity of CVE-2021-41840 is high with a score of 8.2.
Insyde InsydeH2O versions between 5.2 and 5.23.35, between 5.3 and 5.32.35, and between 5.4 and 5.40.35 are affected by CVE-2021-41840.
An attacker can exploit CVE-2021-41840 by leveraging an SMM callout in NvmExpressDxe to access System Management Mode and execute arbitrary code.
Please refer to the vulnerability references for information on available patches or fixes for CVE-2021-41840.