Insyde InsydeH2O
cpe:2.3:a:insyde:insydeh20:*:*:*:*:*:*:*
- >= 5.4, < 05.47.01
- >= 5.5, < 05.55.01
- >= 5.6, < 05.62.01
- >= 5.7, < 05.71.01
A vulnerability has been identified in the UsbCoreDxe component of Insyde InsydeH2O versions 5.4 prior to 05.47.01, 5.5 prior to 05.55.01, 5.6 prior to 05.62.01, and 5.7 prior to 05.71.01. This vulnerability arises from improper input validation, which can be exploited to write arbitrary memory within SMRAM and execute arbitrary code at the SMM level.
Exploitation of this vulnerability allows for arbitrary code execution at the SMM level, with the potential to write arbitrary memory inside SMRAM.
Users can upgrade to InsydeH2O versions 05.47.01, 05.55.01, 05.62.01, or 05.71.01 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.