CVE-2023-22613: High severity insyde h2o vulnerability
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22613?
The severity of CVE-2023-22613 is high with a severity value of 8.8.
How does CVE-2023-22613 impact Insyde InsydeH2O?
CVE-2023-22613 allows an attacker to write to an attacker-controlled address in Insyde InsydeH2O with kernel versions 5.0 through 5.5, resulting in SMM memory corruption.
Is there a fix available for CVE-2023-22613?
Yes, Insyde has released patches to address the vulnerability. Please refer to their security pledge for more information.
Where can I find more information about CVE-2023-22613?
You can find more information about CVE-2023-22613 in the following references: [link 1], [link 2], [link 3].
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-22613?
The Common Weakness Enumeration (CWE) ID for CVE-2023-22613 is CWE-787.