First published: Thu Feb 03 2022(Updated: )
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.0<5.08.29 | |
Insyde InsydeH2O | >=5.1<5.16.29 | |
Insyde InsydeH2O | >=5.2<5.26.29 | |
Insyde InsydeH2O | >=5.3<5.35.29 | |
Insyde InsydeH2O | >=5.4<5.43.29 | |
Insyde InsydeH2O | >=5.5<5.51.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-41841.
The severity of CVE-2021-41841 is rated as high with a severity value of 8.2.
Insyde InsydeH2O versions between 5.0 and 5.5 are affected by CVE-2021-41841.
An attacker can exploit CVE-2021-41841 by leveraging an SMM callout to access System Management Mode and execute arbitrary code.
More information about CVE-2021-41841 can be found at the following references: [link1], [link2], [link3].