First published: Wed Apr 12 2023(Updated: )
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.2<=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22616 is a vulnerability in Insyde InsydeH2O with kernel versions 5.2 through 5.5 that allows an attacker to corrupt SMRAM.
CVE-2023-22616 has a severity score of 7.8, which is considered high.
The Insyde InsydeH2O software with kernel versions 5.2 through 5.5 is affected by CVE-2023-22616.
An attacker can exploit CVE-2023-22616 by taking advantage of the Save State register that is not checked before use in the IhisiSmm driver.
Yes, you can find more information about CVE-2023-22616 at the following references: [Link 1](https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/), [Link 2](https://www.insyde.com/security-pledge), [Link 3](https://www.insyde.com/security-pledge/SA-2023022).