CVE-2023-22612: Insyde INSYDEH2O

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.

Affected products

  • Insyde INSYDEH2O: version 05.0a.11 only; version 05.18.03 only; version 05.28.03 only; version 05.37.03 only; version 05.45.01 only; version 05.53.01 only

Published 2023-04-11. Last modified 2026-06-17.