An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.insyde.com/security-pledge | not applicable |
https://www.insyde.com/security-pledge/SA-2023028 | vendor advisory |