CVE-2020-5953

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Configurations

Configuration 1

cpe:2.3:a:insyde:insydeh2o:5.34.03.0029:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.45.0023:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.23.04.0045:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.42.03.0010:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.33.15.0034:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:5.12.09.0074:*:*:*:*:*:*:*

Information

Published : 2022-02-03 01:15

Updated : 2022-04-12 06:17


NVD link : CVE-2020-5953

Mitre link : CVE-2020-5953