An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-02T00:00:00
Updated: 2024-09-05T15:24:35.544Z
Reserved: 2023-07-27T00:00:00
Link: CVE-2023-39283
Updated: 2024-08-02T18:02:06.868Z
Status : Modified
Published: 2023-11-02T22:15:09.070
Modified: 2024-11-21T08:15:03.690
Link: CVE-2023-39283
No data.