Lucene search

K
cveMitreCVE-2021-41839
HistoryFeb 03, 2022 - 2:15 a.m.

CVE-2021-41839

2022-02-0302:15:07
CWE-119
mitre
web.nvd.nist.gov
58
nvmexpressdxe
insydeh2o
kernel 5.0
kernel 5.5
smm memory corruption
untrusted pointer dereference
cve-2021-41839

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0

Percentile

5.1%

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

Affected configurations

Nvd
Node
insydeinsydeh2oRange5.15.16.25
Node
insydeinsydeh2oRange5.25.26.25
Node
insydeinsydeh2oRange5.35.35.25
Node
insydeinsydeh2oRange5.45.43.25
Node
insydeinsydeh2oRange5.55.51.25
VendorProductVersionCPE
insydeinsydeh2o*cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2021-41839