First published: Sat Dec 16 2023(Updated: )
TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an attacker to alter data and code used by the remainder of the boot process.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O UEFI BIOS | >=5.2<5.2.05.27.29 | |
Insyde InsydeH2O UEFI BIOS | >=5.3<5.3.05.36.29 | |
Insyde InsydeH2O UEFI BIOS | >=5.4<5.4.05.44.13 | |
Insyde InsydeH2O UEFI BIOS | >=5.5<5.5.05.52.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24351 is categorized with a medium severity level as it involves a TOCTOU race-condition vulnerability.
To fix CVE-2022-24351, you should update the InsydeH2O UEFI BIOS to a version that is not affected by the vulnerability.
CVE-2022-24351 affects InsydeH2O UEFI BIOS versions prior to 05.27.29 for Kernel 5.2, 05.36.29 for Kernel 5.3, 05.44.13 for Kernel 5.4, and 05.52.13 for Kernel 5.5.
CVE-2022-24351 typically requires local access to the system, making remote exploitation unlikely.
CVE-2022-24351 is a TOCTOU race-condition vulnerability that allows an attacker to alter data and code during the boot process.