First published: Thu Nov 02 2023(Updated: )
An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.0<=5.5 | |
Insyde InsydeH2O | =5.5.05.53.22 | |
Insyde InsydeH2O | =5.6 | |
Insyde InsydeH2O | =5.6.05.60.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39283 is an SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
An attacker can exploit CVE-2023-39283 by sending arbitrary data to SMM, which could lead to privilege escalation.
The severity of CVE-2023-39283 is high with a CVSS score of 7.8.
Insyde InsydeH2O versions 5.0 through 5.5 are affected by CVE-2023-39283.
To fix CVE-2023-39283, update to a version of Insyde InsydeH2O that is later than 5.5 or apply any patches provided by the vendor.