系微安全保證

最新安全公告

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2022011SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022010SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022009SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022008SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022007SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022006Stack overflow vulnerability that allows a local root user to access UEFI DXE driver and execute arbitrary code.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022001A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022005SdLegacySmm: Software SMI handler does not verify CommBuffer, allowing untrusted external input (CVE-2020-5956).
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022004AtaLegacySmm: SMI handler does not check CommBuffer leading to possible arbitrary code execution.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022003A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(CommBuffer + 8 location). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022002A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(status code saved at CommBuffer+4 location). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022001A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(CommBufferData). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.
8.2