CRITICAL · 9.8

CVE-2020-5955

An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.

Vulnerability Description

An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
InsydeInsydeh2O Uefi Bios< 05.32.30.0001
IntelIce Lake-
IntelTiger Lake-
IntelWhitley-Sp-
IntelGrantley-Ep-
IntelElkhart Lake-
IntelPurley-Ep Refresh Neon City-
IntelComet Lake Rvp-
IntelComet Lake-
IntelWhiskey Lake Rvp-
IntelWhiskey Lake-
IntelMehlow-
IntelMehlow-R-
IntelCoffee Lake-
IntelCannon Lake-
IntelKaby Lake Mrd-
IntelGreenlow-
IntelGreenlow-R-
IntelKaby Lake-
IntelSkylake Mrd-

References

FAQ

What is CVE-2020-5955?

CVE-2020-5955 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.

How severe is CVE-2020-5955?

CVE-2020-5955 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-5955?

Check the references section above for vendor advisories and patch information. Affected products include: Insyde Insydeh2O Uefi Bios, Intel Ice Lake, Intel Tiger Lake, Intel Whitley-Sp, Intel Grantley-Ep.