CVE-2021-42060: High severity Insyde InsydeH2O vulnerability
An issue was discovered in Insyde InsydeH2O Kernel 5.0 through 05.08.41, Kernel 5.1 through 05.16.41, Kernel 5.2 before 05.23.22, and Kernel 5.3 before 05.32.22. An Int15ServiceSmm SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-42060.
What is the severity rating of CVE-2021-42060?
CVE-2021-42060 has a severity rating of 8.2 (high).
Which software versions are affected by CVE-2021-42060?
CVE-2021-42060 affects Insyde InsydeH2O Kernel versions 5.0 through 05.08.41, 5.1 through 05.16.41, 5.2 before 05.23.22, and 5.3 before 05.32.22.
What is the impact of CVE-2021-42060?
CVE-2021-42060 allows an attacker to hijack execution flow of code running in System Management Mode (SMM).
Are there any known fixes or mitigation steps for CVE-2021-42060?
To mitigate CVE-2021-42060, it is recommended to apply the necessary security patches provided by Insyde or follow the guidance provided in the vendor's security advisory.