CVE-2022-32474 affects Insyde InsydeH2O firmware kernels 5.0 through 5.5. It describes a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability arising from DMA attacks on a shared buffer between SMM and non-SMM code. This flaw carries a CVSSv3.1 score of 7.0 (HIGH), indicating that a local attacker with low privileges and high attack complexity could achieve SMRAM corruption and privilege escalation. While the vulnerability is significant, there is currently no evidence of active exploitation, publicly available exploit code, or notable community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.0.05.09.42CPE matchmatch criteria | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* | ||
>= 5.1, < 5.1.05.17.42CPE matchmatch criteria | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2.05.27.38CPE matchmatch criteria | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* | ||
>= 5.3, < 5.3.05.36.38CPE matchmatch criteria | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* | ||
>= 5.4, < 5.4.05.44.38CPE matchmatch criteria | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.