CVE-2022-32475: High severity insyde h2o vulnerability
Published Feb 15, 2023
·Updated
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.
Affected Software
4 affected components
Insyde InsydeH2O>=5.0<5.2.05.27.27
Insyde InsydeH2O>=5.3<5.3.05.36.27
Insyde InsydeH2O>=5.4<5.4.05.44.27
Insyde InsydeH2O>=5.5<5.5.05.52.27
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-32475.
2
What is the severity of CVE-2022-32475?
CVE-2022-32475 has a severity rating of high.
3
How does CVE-2022-32475 affect the Insyde InsydeH2O software?
CVE-2022-32475 affects the Insyde InsydeH2O software versions 5.0 through 5.5.
4
What is the impact of CVE-2022-32475?
CVE-2022-32475 can lead to corruption of SMRAM and escalation of privileges.
5
How can CVE-2022-32475 be fixed?
The issue has been fixed in the kernel of Insyde InsydeH2O software.