CVE-2022-32475

HIGH

Insyde InsydeH2O 5.0-5.5 - Time-of-check Time-of-use Race Condition via VariableRuntimeDxe Shared Buffer

Title source: llm
STIX 2.1

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.

References (2)

Core 2

Scores

CVSS v3 7.0
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Products (1)
insyde/insydeh2o 5.0 - 5.2.05.27.27
Published Feb 15, 2023
Tracked Since Feb 18, 2026