CVE-2022-35895: High severity insyde h2o vulnerability
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input parameters for a software SMI routine, leading to memory corruption of arbitrary addresses including SMRAM, and possible arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35895?
CVE-2022-35895 is a vulnerability discovered in Insyde InsydeH2O with kernel 5.0 through 5.5 that allows for memory corruption and possible arbitrary code execution.
How does CVE-2022-35895 affect Insyde InsydeH2O?
CVE-2022-35895 affects Insyde InsydeH2O versions 5.0 through 5.5.
What is the severity of CVE-2022-35895?
The severity of CVE-2022-35895 is high with a CVSS score of 8.2.
How can the CVE-2022-35895 vulnerability be fixed?
To fix the CVE-2022-35895 vulnerability, update Insyde InsydeH2O to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-35895?
You can find more information about CVE-2022-35895 at the following references: [Reference 1](https://binarly.io/advisories/BRLY-2022-024/index.html), [Reference 2](https://www.insyde.com/security-pledge), [Reference 3](https://www.insyde.com/security-pledge/SA-2022033).