PoC Index

CVE-2023-22614

HIGH 8.8EPSS 0.4%

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
0.38% chance of exploitation in the next 30 days, 31th percentile
Published
2023-04-11
Updated
2025-02-11

Proof-of-concept exploits (1)

References

Related