系微安全保證

最新安全公告

Security Advisory Archives

BIOS & BMC

Link
Summary
CVSS Score
INSYDE-SA-2022059SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM.
8.2
Link
Summary
CVSS Score
INSYDE-SA-2022058In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022043DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents of parameter values (a TOCTOU attack).
7.5
Link
Summary
CVSS Score
INSYDE-SA-2022057DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022056DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack.
7.4
Link
Summary
CVSS Score
INSYDE-SA-2022055DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022054DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM corruption through a TOCTOU attack.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022053DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU attack.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022052DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM.
7.4
Link
Summary
CVSS Score
INSYDE-SA-2022051DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU attack.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022050DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU attack.
7.8
Link
Summary
CVSS Score
INSYDE-SA-2022049DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack.
8.2