系微安全保證
最新安全公告

Security Advisory Archives
BIOS & BMC
InsydeH2O | 2022年02月1日 : SA-2022017
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022017 | A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2). | 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022016
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022016 | SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. | 8.2 |
InsydeH2O | 2022年02月1日 : SA-2022015
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022015 | SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. | 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022014
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022014 | SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
| 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022013
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022013 | SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. | 8.2 |
InsydeH2O | 2022年02月1日 : SA-2022012
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022012 | SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. | 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022011
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022011 | SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. | 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022010
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022010 | SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. | 8.2 |
InsydeH2O | 2022年02月1日 : SA-2022009
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022009 | SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. | 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022008
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022008 | SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. | 8.2 |
InsydeH2O | 2022年02月1日 : SA-2022007
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022007 | SMM callout vulnerability allowing a possible attacker to hijack execution flow of a code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM. | 7.5 |
InsydeH2O | 2022年02月1日 : SA-2022006
| Link | Summary | CVSS Score |
|---|---|---|
| INSYDE-SA-2022006 | Stack overflow vulnerability that allows a local root user to access UEFI DXE driver and execute arbitrary code. | 8.2 |