CVE-2022-36337: Buffer Overflow
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36337?
CVE-2022-36337 is a vulnerability in Insyde InsydeH2O with kernel 5.0 through 5.5 that allows for a stack buffer overflow and arbitrary code execution.
How does CVE-2022-36337 affect InsydeH2O?
CVE-2022-36337 affects InsydeH2O with kernel 5.0 through 5.5 by exploiting a stack buffer overflow vulnerability in the MebxConfiguration driver, resulting in arbitrary code execution.
What is the severity of CVE-2022-36337?
CVE-2022-36337 has a severity rating of 8.2 out of 10, indicating a high risk.
How can I fix CVE-2022-36337?
To fix CVE-2022-36337, it is recommended to apply the latest security patches and updates provided by Insyde, and follow their security guidelines.
Are there any references for CVE-2022-36337?
Yes, you can find references for CVE-2022-36337 at the following links: [Link 1](https://www.insyde.com/security-pledge) and [Link 2](https://www.insyde.com/security-pledge/SA-2022039).