An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable exceeds the size of the first, then the buffer will be overwritten. This issue affects the SetupUtility driver of InsydeH2O.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2022-11-22T00:00:00.000Z
Updated: 2025-04-29T15:18:52.345Z
Reserved: 2022-07-08T00:00:00.000Z
Link: CVE-2022-35407

Updated: 2024-08-03T09:36:43.358Z

Status : Modified
Published: 2022-11-22T02:15:09.120
Modified: 2025-04-29T16:15:23.800
Link: CVE-2022-35407

No data.