CVE-2023-39283: High severity insyde h2o vulnerability
An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39283?
CVE-2023-39283 is an SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5.
How can an attacker exploit CVE-2023-39283?
An attacker can exploit CVE-2023-39283 by sending arbitrary data to SMM, which could lead to privilege escalation.
What is the severity of CVE-2023-39283?
The severity of CVE-2023-39283 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2023-39283?
Insyde InsydeH2O versions 5.0 through 5.5 are affected by CVE-2023-39283.
How can I fix CVE-2023-39283?
To fix CVE-2023-39283, update to a version of Insyde InsydeH2O that is later than 5.5 or apply any patches provided by the vendor.