CVE-2023-25600: High severity insyde insydeh2o uefi bios vulnerability
An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue with InsydeH2O?
The vulnerability ID for this issue with InsydeH2O is CVE-2023-25600.
What is the severity of CVE-2023-25600?
The severity of CVE-2023-25600 is high with a CVSS score of 7.1.
How does the vulnerability in InsydeH2O occur?
The vulnerability in InsydeH2O occurs when a malicious operating system tampers with a runtime-writable EFI variable, causing out-of-bounds memory reads and a denial of service.
Which version of InsydeH2O fixes CVE-2023-25600?
CVE-2023-25600 is fixed in version 01.01.04.0016 of InsydeH2O.
Where can I find more information about CVE-2023-25600?
You can find more information about CVE-2023-25600 at the following links: - [Insyde Security Pledge - SA-2023028](https://www.insyde.com/security-pledge/SA-2023028) - [Insyde Security Pledge](https://www.insyde.com/security-pledge)