Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-10285
HistoryFeb 08, 2022 - 12:00 a.m.

Insyde InsydeH2O Buffer Overflow Vulnerability (CNVD-2022-10285)

2022-02-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
13

0.001 Low

EPSS

Percentile

20.6%

Insyde InsydeH2O is a C source from Insyde Software (Taiwan, China) that implements the new technology “EFI/UEFI” specification, designed to replace the legacy BIOS (Basic Input/Output System). Operating System (H2O) UEFI firmware suffers from a buffer overflow vulnerability that stems from the SWSMI handler not adequately checking or validating the allocated buffer pointer (CommBuffer), which could be exploited to corrupt data in SMRAM memory, leading to arbitrary code execution.

0.001 Low

EPSS

Percentile

20.6%

Related for CNVD-2022-10285