CVE-2024-25078
HIGHDescription
A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.
Is your site exposed to CVE-2024-25078?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| insyde | kernel |
| insyde | kernel |
| insyde | kernel |
| insyde | kernel |
| insyde | kernel |
References
Frequently Asked Questions
What is CVE-2024-25078? +
How severe is CVE-2024-25078? +
What products are affected by CVE-2024-25078? +
How do I check if I'm vulnerable to CVE-2024-25078? +
Related Vulnerabilities
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local …
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow …
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM …
Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a …
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.