CVE-2023-22613: Insyde INSYDEH2O
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
Affected products
- Insyde INSYDEH2O: version 05.27.37 only; version 05.36.37 only; version 05.44.45 only; version 05.52.45 only
Published 2023-04-11. Last modified 2026-06-17.