ZeroHour

CVE-2023-39284

CVSS 3.1
5.5 medium
EPSS
<1%p7
Published
()
Modified
Description

An issue was discovered in IhisiServicesSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There are arbitrary calls to SetVariable with unsanitized arguments in the SMI handler.

Vendors
insyde
Products
insydeh2o
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.