CVE-2022-32474

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the StorageSecurityCommandDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation...
https://cyberfishnews.com/cve-2022-32474-116404.html?utm_source=dlvr.it&utm_medium=blogger&utm_campaign=techfishnews

Comments