Lenovo Insyde BIOS Vulnerability Allowing Improper Input Validation in SMM Module
Vulnerability
A vulnerability has been identified in the InsydeH2O BIOS code developed for Lenovo. This vulnerability involves arbitrary calls to the SmmSetVariable function with unsanitized arguments in the System Management Mode (SMM) handler, which can lead to memory corruption. The issue arises from improper input validation, allowing potentially harmful data to be processed without adequate checks.
Impact
Exploitation of this vulnerability could lead to arbitrary memory corruption within the SMM module, a critical area of the system firmware that manages hardware resources and can execute privileged code.
Remediation
Users can update to the Lenovo feature version L05.05.40.011803.172079 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
