8.2highHigh

CVE-2021-42113

Insyde Insydeh2o

An issue was discovered in StorageSecurityCommandDxe in Insyde InsydeH2O with Kernel 5.1 before 05.14.28, Kernel 5.2 before 05.24.28, and Kernel 5.3 before 05.32.25. An SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an administrative account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
8.2 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Assigned by
cve@mitre.org

Dates

Published
2022-02-03
Last modified
2026-08-11
Sources
NVD

Affected products

  • Insyde Insydeh2o5.1 - 5.14.34, 5.2 - 5.24.34, 5.3 - 5.24.34

As listed in the NVD configuration data. Not a statement about your estate.

References