CVE-2023-39281: Insyde INSYDEH2O

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

Affected products

  • Insyde INSYDEH2O: version 05.45.24.0039 only; version 05.44.45.0017 only; version 05.44.34.0055 only; version 05.53.28.0013 only; version 05.45.38.0005 only; version 05.53.23.0011 only; …

Published 2023-11-01. Last modified 2026-06-17.