CVE-2024-25078: High severity insyde h2o vulnerability
A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25078?
The severity of CVE-2024-25078 is considered critical due to its potential to lead to privilege escalation.
How do I fix CVE-2024-25078?
To fix CVE-2024-25078, update your InsydeH2O UEFI BIOS to the latest version as specified in the vendor advisories.
Which versions of InsydeH2O are affected by CVE-2024-25078?
CVE-2024-25078 affects InsydeH2O versions prior to 5.2 and specific versions 5.3 through 5.6 as listed in the vulnerability details.
What type of vulnerability is CVE-2024-25078?
CVE-2024-25078 is characterized as a memory corruption vulnerability.
Can CVE-2024-25078 be exploited remotely?
CVE-2024-25078 is primarily a local privilege escalation vulnerability and typically requires local access for exploitation.