VYPR
High severity7.8NVD Advisory· Published Nov 22, 2022· Updated Jun 17, 2026

CVE-2022-35407

CVE-2022-35407

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable exceeds the size of the first, then the buffer will be overwritten. This issue affects the SetupUtility driver of InsydeH2O.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Insyde/InsydeH2Odescription
  • Insyde/InsydeH2Ollm-fuzzy
    Range: 5.0-5.5
  • cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
    Range: >=5.0,<=5.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.