Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 before 05.14.28, Kernel 5.2 before 05.24.28, and Kernel 5.3 before 05.32.25. An SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Insyde InsydeH2O 权限许可和访问控制问题漏洞
Vulnerability Description
Insyde InsydeH2O是中国台湾系微(Insyde)公司的一个 C 语言源,它实现了新技术“EFI/UEFI”规范,旨在取代传统的 BIOS(基本输入/输出系统)。 InsydeH2O Hardware-2-Operating System (H2O) UEFI固件存在权限许可和访问控制问题漏洞,该漏洞允许可能的攻击者劫持在系统管理模式下运行的代码的执行流程。利用此问题可能会导致 SMM 的权限升级。
CVSS Information
N/A
Vulnerability Type
N/A