CVE-2021-41841: High severity Insyde InsydeH2O vulnerability
Published Feb 3, 2022
·Updated
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.
Affected Software
6 affected components
Insyde InsydeH2O>=5.0<5.08.29
Insyde InsydeH2O>=5.1<5.16.29
Insyde InsydeH2O>=5.2<5.26.29
Insyde InsydeH2O>=5.3<5.35.29
Insyde InsydeH2O>=5.4<5.43.29
Insyde InsydeH2O>=5.5<5.51.29
Event History
Feb 3, 2022
CVE Published
via MITRE·01:04 AM
Data Sourced
via MITRE·01:04 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-41841.
2
What is the severity of CVE-2021-41841?
The severity of CVE-2021-41841 is rated as high with a severity value of 8.2.
3
What software is affected by CVE-2021-41841?
Insyde InsydeH2O versions between 5.0 and 5.5 are affected by CVE-2021-41841.
4
How can an attacker exploit CVE-2021-41841?
An attacker can exploit CVE-2021-41841 by leveraging an SMM callout to access System Management Mode and execute arbitrary code.
5
Where can I find more information about CVE-2021-41841?
More information about CVE-2021-41841 can be found at the following references: [link1], [link2], [link3].