First published: Thu Nov 14 2024(Updated: )
Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3, version 05.38.19; kernel 5.4, version 05.46.19; kernel 5.5, version 05.54.19; kernel 5.6, version 05.61.19.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde IhisiServiceSmm | <05.29.19 | |
Kernel | >=5.2<5.3>=5.3<5.4>=5.4<5.5>=5.5<5.6<05.54.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39707 has a high-severity rating due to its potential to allow unauthorized restoration of UEFI variables, leading to possible rollback attacks.
To fix CVE-2024-39707, update the Insyde IHISI function to kernel version 5.2 (05.29.19) or later.
CVE-2024-39707 affects certain platforms utilizing the Insyde IHISI function and specific versions of the kernel.
CVE-2024-39707 may not directly lead to remote exploits but it can enable attackers to perform rollback attacks locally.
Currently, there are no official workarounds for CVE-2024-39707, and applying the update is recommended as the most effective mitigation.