High severity8.2NVD Advisory· Published Sep 21, 2022· Updated Jun 17, 2026
CVE-2022-35895
CVE-2022-35895
Description
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input parameters for a software SMI routine, leading to memory corruption of arbitrary addresses including SMRAM, and possible arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Insyde/InsydeH2Odescription
Patches
Vulnerability mechanics
References
3- binarly.io/advisories/BRLY-2022-024/index.htmlnvdExploitThird Party Advisory
- www.insyde.com/security-pledgenvdVendor Advisory
- www.insyde.com/security-pledge/SA-2022033nvdVendor Advisory
News mentions
0No linked articles in our index yet.