High severity8.8NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2023-22613
CVE-2023-22613
Description
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:insyde:insydeh2o:05.27.37:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:insyde:insydeh2o:05.27.37:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.36.37:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.44.45:*:*:*:*:*:*:*
- cpe:2.3:a:insyde:insydeh2o:05.52.45:*:*:*:*:*:*:*
- (no CPE)range: 5.0-5.5
- Insyde/InsydeH2Odescription
Patches
Vulnerability mechanics
References
3- www.insyde.com/security-pledgenvdVendor Advisory
- www.insyde.com/security-pledge/SA-2023023nvdVendor Advisory
- research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/nvdNot Applicable
News mentions
0No linked articles in our index yet.