Vulnerability Description
An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory corruption or a system crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insyde | H2Offt | 6.20.00 |
| Insyde | Iscflashx64.Sys | 3.9.3.0 |
Related Weaknesses (CWE)
References
- https://www.insyde.com/security-pledgeNot Applicable
- https://www.insyde.com/security-pledge/SA-2021004Vendor Advisory
- https://www.insyde.com/security-pledgeNot Applicable
- https://www.insyde.com/security-pledge/SA-2021004Vendor Advisory
FAQ
What is CVE-2021-33834?
CVE-2021-33834 is a vulnerability with a CVSS score of 7.1 (HIGH). An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory co...
How severe is CVE-2021-33834?
CVE-2021-33834 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33834?
Check the references section above for vendor advisories and patch information. Affected products include: Insyde H2Offt, Insyde Iscflashx64.Sys.