Buffer Overflow Vulnerability in UEFI Variable Handling by Insyde
CVE-2021-43614

6.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2021-43614?

A vulnerability in the management of the PlatformLangCodes UEFI variable can lead to a buffer overflow. This issue may result in resource exhaustion, causing system malfunctions and failures. System administrators and users are urged to review their UEFI configurations and apply necessary updates to mitigate this risk.

Affected Version(s)

InsydeH2O x86 InsydeH2OUvePkg < 01.01.04.0008

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.