UEFI Variable Modification Vulnerability in InsydeH2O Firmware
CVE-2023-28149

Currently unrated

Key Information:

Vendor
CVE Published:
31 July 2024

What is CVE-2023-28149?

InsydeH2O firmware contains a flaw in the IhisiServiceSmm module that enables the modification of UEFI variables. This could allow attackers to alter system settings, potentially leading to unauthorized access, firmware manipulation, and compromise of system integrity. Affected versions include those prior to specific updates across several major firmware releases. Users of InsydeH2O are advised to update their systems to the latest versions to mitigate the associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.