ZeroHour

CVE-2023-39281

CVSS 3.1
9.8 critical
EPSS
<1%p40
Published
()
Modified
Description

A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

Vendors
insyde
Products
insydeh2o
Weakness
CWE-787, CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.