Memory Corruption Vulnerability in InsydeH2O Firmware
CVE-2024-25078
7.4HIGH
What is CVE-2024-25078?
A memory corruption vulnerability exists within the StorageSecurityCommandDxe module of InsydeH2O firmware, which can lead to privilege escalation within System Management Mode (SMM). This vulnerability impacts multiple kernel versions, specifically versions 5.2 through 5.6, prior to specific builds. Successful exploitation could allow an attacker to manipulate system-level functions, potentially compromising sensitive operations and leading to unauthorized access. Addressing this issue requires updating firmware to secure builds as outlined in Insyde's security pledges.
