ZeroHour

CVE-2021-33834

CVSS 3.1
7.1 high
EPSS
<1%p9
Published
()
Modified
Description

An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory corruption or a system crash.

Vendors
insyde
Products
h2offt, iscflashx64.sys
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.