An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.insyde.com/security-pledge | vendor advisory |
https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/ | not applicable |
https://www.insyde.com/security-pledge/SA-2023019 | vendor advisory |