CVE-2022-24351: Medium severity insyde h2o vulnerability
TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an attacker to alter data and code used by the remainder of the boot process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24351?
CVE-2022-24351 is categorized with a medium severity level as it involves a TOCTOU race-condition vulnerability.
How do I fix CVE-2022-24351?
To fix CVE-2022-24351, you should update the InsydeH2O UEFI BIOS to a version that is not affected by the vulnerability.
What systems are affected by CVE-2022-24351?
CVE-2022-24351 affects InsydeH2O UEFI BIOS versions prior to 05.27.29 for Kernel 5.2, 05.36.29 for Kernel 5.3, 05.44.13 for Kernel 5.4, and 05.52.13 for Kernel 5.5.
Can CVE-2022-24351 be exploited remotely?
CVE-2022-24351 typically requires local access to the system, making remote exploitation unlikely.
What type of vulnerability is CVE-2022-24351?
CVE-2022-24351 is a TOCTOU race-condition vulnerability that allows an attacker to alter data and code during the boot process.