CVE-2021-42060
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Insyde InsydeH2O Kernel 5.0 through 05.08.41, Kernel 5.1 through 05.16.41, Kernel 5.2 before 05.23.22, and Kernel 5.3 before 05.32.22. An Int15ServiceSmm SMM callout vulnerability allows an attacker to hijack execution flow of code running in System Management Mode. Exploiting this issue could lead to escalating privileges to SMM.
Se ha descubierto un problema en el Kernel InsydeH2O 5.0 hasta la versión 05.08.41, en el Kernel 5.1 hasta la versión 05.16.41, en el Kernel 5.2 hasta la versión 05.23.22 y en el Kernel 5.3 hasta la versión 05.32.22. Una vulnerabilidad de la llamada Int15ServiceSmm SMM permite a un atacante secuestrar el flujo de ejecución del código que se ejecuta en el modo de gestión del sistema. La explotación de este problema podría conducir a la escalada de privilegios al SMM
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-07 CVE Reserved
- 2022-02-03 CVE Published
- 2023-09-24 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20220217-0015 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.insyde.com/security-pledge | 2022-03-29 | |
https://www.insyde.com/security-pledge/SA-2022007 | 2022-03-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.2 < 5.23.35 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.2 < 5.23.35" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.3 < 5.32.35 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.3 < 5.32.35" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.1 < 5.16.42 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.1 < 5.16.42" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Insydeh2o Search vendor "Insyde" for product "Insydeh2o" | >= 5.0 < 05.08.49 Search vendor "Insyde" for product "Insydeh2o" and version " >= 5.0 < 05.08.49" | - |
Affected
|