Total vulnerabilities in the database
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Software | From | Fixed in |
---|---|---|
insyde / insydeh2o | 5.34.03.0029 | 5.34.03.0029.x |
insyde / insydeh2o | 5.23.45.0023 | 5.23.45.0023.x |
insyde / insydeh2o | 5.23.04.0045 | 5.23.04.0045.x |
insyde / insydeh2o | 5.42.03.0010 | 5.42.03.0010.x |
insyde / insydeh2o | 5.33.15.0034 | 5.33.15.0034.x |
insyde / insydeh2o | 5.12.09.0074 | 5.12.09.0074.x |