First published: Wed May 15 2024(Updated: )
A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O UEFI BIOS | <5.2>=5.3<=5.3>=5.4<=5.4>=5.5<=5.5>=5.6<=5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-25078 is considered critical due to its potential to lead to privilege escalation.
To fix CVE-2024-25078, update your InsydeH2O UEFI BIOS to the latest version as specified in the vendor advisories.
CVE-2024-25078 affects InsydeH2O versions prior to 5.2 and specific versions 5.3 through 5.6 as listed in the vulnerability details.
CVE-2024-25078 is characterized as a memory corruption vulnerability.
CVE-2024-25078 is primarily a local privilege escalation vulnerability and typically requires local access for exploitation.