Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Insyde InsydeH2O 缓冲区错误漏洞
Vulnerability Description
Insyde InsydeH2O是中国台湾系微(Insyde)公司的一个 C 语言源,它实现了新技术“EFI/UEFI”规范,旨在取代传统的 BIOS(基本输入/输出系统)。 InsydeH2O Hardware-2-Operating System (H2O) UEFI固件存在安全漏洞,攻击者可以使用这个不安全的指针current_ptr来读取或写入或操作数据到 SMRAM。利用此漏洞可能会导致使用 SwSMI 处理程序仅为 SMM 保留的权限升级。
CVSS Information
N/A
Vulnerability Type
N/A