High severity8.8NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2023-22612
CVE-2023-22612
Description
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:insyde:insydeh2o:05.0a.11:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:insyde:insydeh2o:05.0a.11:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.18.03:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.28.03:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.37.03:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.45.01:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.53.01:*:*:*:*:*:*:*
- (no CPE)range: 5.0-5.5
- Insyde/InsydeH2Odescription
Patches
Vulnerability mechanics
References
3- www.insyde.com/security-pledgenvdVendor Advisory
- www.insyde.com/security-pledge/SA-2023019nvdVendor Advisory
- research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/nvdNot Applicable
News mentions
0No linked articles in our index yet.