CVE-2021-41839

HIGH

InsydeH2O 5.1-5.5 - Untrusted Pointer Dereference in NvmExpressDxe

Title source: llm
STIX 2.1

Description

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge/SA-2022020
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220217-0016/
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/796611

Scores

CVSS v3 8.2
EPSS 0.0027
EPSS Percentile 19.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
insyde/insydeh2o 5.1 - 5.16.25
Published Feb 03, 2022
Tracked Since Feb 18, 2026