CVE-2024-55567

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The SMM module has an SMM call out vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
Configurations

No configuration.

History

17 Jun 2025, 19:15

Type Values Removed Values Added
CWE CWE-20

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Se detectó una validación de entrada incorrecta en UsbCoreDxe en el kernel InsydeH2O 5.4 anterior a 05.47.01, 5.5 anterior a 05.55.01, 5.6 anterior a 05.62.01 y 5.7 anterior a 05.71.01. El módulo SMM presenta una vulnerabilidad de llamada a SMM que permite escribir memoria arbitraria dentro de SMRAM y ejecutar código arbitrario a nivel de SMM.

12 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 17:15

Updated : 2025-06-17 19:15


NVD link : CVE-2024-55567

Mitre link : CVE-2024-55567

CVE.ORG link : CVE-2024-55567


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation