Arbitrary Memory Write Vulnerability in Insyde Software’s UsbCoreDxe Product
CVE-2025-4276
7.5HIGH
What is CVE-2025-4276?
The UsbCoreDxe component within Insyde Software has a vulnerability that enables attackers to write arbitrary memory in System Management RAM (SMRAM). This flaw could lead to the execution of malicious code at the System Management Mode (SMM) level, potentially allowing unauthorized operations or compromise of the system.
Affected Version(s)
InsydeH2O Kernel 5.3 < 05.39.18
InsydeH2O Kernel 5.5 < 05.55.18
InsydeH2O Kernel 5.6 < 05.62.18