VYPR

IhisiSmm

by Insyde

CVEs (3)

  • CVE-2023-22612HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.

  • CVE-2022-32471HigFeb 15, 2023
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the command buffer contents with DMA after the input parameters have been checked but before they are…

  • CVE-2022-30773MedNov 14, 2022
    risk 0.42cvss 6.4epss 0.00

    DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after…