CVE-2022-35893

HIGH

InsydeH2O <5.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge
Vendor Advisory x_refsource_misc
https://www.insyde.com/security-pledge/SA-2022035
Third Party Advisory x_refsource_misc
https://binarly.io/advisories/BRLY-2022-026/index.html

Scores

CVSS v3 8.2
EPSS 0.0021
EPSS Percentile 11.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
insyde/insydeh2o 5.0 - 05.09.37
Published Sep 23, 2022
Tracked Since Feb 18, 2026