ZeroHour

CVE-2022-35894

PoC
CVSS 3.1
6.0 medium
EPSS
<1%p25
Published
()
Modified
Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.

Vendors
insyde
Products
insydeh2o
Weakness
CWE-401
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.