CVE-2022-32471: High severity insyde h2o vulnerability
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the command buffer contents with DMA after the input parameters have been checked but before they are used, the IHISI SMM code may be convinced to modify SMRAM or OS, leading to possible data corruption or escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32471?
The severity of CVE-2022-32471 is high.
What software versions are affected by CVE-2022-32471?
Insyde InsydeH2O versions 5.0 through 5.5 are affected by CVE-2022-32471.
How does CVE-2022-32471 affect Insyde InsydeH2O?
CVE-2022-32471 affects Insyde InsydeH2O by allowing modification of the command buffer contents with DMA, leading to potential security vulnerabilities.
Are there any patches or fixes available for CVE-2022-32471?
For information on patches or fixes for CVE-2022-32471, please refer to the Insyde Security Pledge website.
Where can I find more information about CVE-2022-32471?
For more information about CVE-2022-32471, please refer to the Insyde Security Pledge website or the provided references.