CVE-2023-22616

HIGH

Insyde InsydeH2O 5.2-5.5 - SMRAM Corruption via IhisiSmm Driver Save State Register

Title source: llm
STIX 2.1

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insufficient input validation, an attacker can corrupt SMRAM.

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 28.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-610
Status published
Products (1)
insyde/insydeh2o 5.2 - 5.5
Published Apr 12, 2023
Tracked Since Feb 18, 2026