Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-10034
HistoryOct 08, 2021 - 12:00 a.m.

Insyde InsydeH2O Memory Corruption Vulnerability

2021-10-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.001 Low

EPSS

Percentile

20.6%

Insyde InsydeH2O is a C source from Insyde Software (Taiwan, China) that implements the new technology “EFI/UEFI” specification, designed to replace the legacy BIOS (Basic Input/Output System).Insyde InsydeH2O suffers from a memory corruption vulnerability. InsydeH2O is vulnerable to memory corruption, which stems from certain SMM drivers in the kernel that do not properly validate the CommBuffer and CommBufferSize parameters, leading to calls to corrupt firmware or OS memory, which can be exploited to cause a denial of service by corrupting the system.

0.001 Low

EPSS

Percentile

20.6%

Related for CNVD-2022-10034