CVE-2023-22614: Insyde INSYDEH2O

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.

Affected products

  • Insyde INSYDEH2O: version 05.42.52.0026 only; version 05.43.01.0026 only; version 05.43.12.0056 only; version 05.44.34.0054 only; version 05.44.45.0015 only; version 05.44.45.0028 only

Published 2023-04-11. Last modified 2026-06-17.