CVE-2022-34325

HIGH

InsydeH2O 5.3-05.36.23 - TOCTOU Race Condition in StorageSecurityCommandDxe SMI Handler

Title source: llm
STIX 2.1

Description

DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the StorageSecurityCommandDxe driver could cause SMRAM corruption. This issue was discovered by Insyde engineering based on the general description provided by

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Products (1)
insyde/insydeh2o 5.3 - 05.36.23
Published Nov 14, 2022
Tracked Since Feb 18, 2026