CVE-2022-35893: Input Validation
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-35893.
What is the severity level of CVE-2022-35893?
The severity level of CVE-2022-35893 is high with a CVSS score of 8.2.
What is the affected software?
The affected software is Insyde InsydeH2O with kernel versions 5.0 through 5.5.
What is the impact of exploiting CVE-2022-35893?
Exploiting CVE-2022-35893 could lead to escalating privileges to SMM (System Management Mode).
Are there any references for more information about CVE-2022-35893?
Yes, you can find more information about CVE-2022-35893 at the following references: [1](https://binarly.io/advisories/BRLY-2022-026/index.html), [2](https://www.insyde.com/security-pledge), [3](https://www.insyde.com/security-pledge/SA-2022035).