Vulnerability Description
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insyde | Insydeh2O | 05.45.24.0039 |
| Intel | B760 | - |
| Intel | C262 | - |
| Intel | C266 | - |
| Intel | Core I3-1305U | - |
| Intel | Core I3-13100 | - |
| Intel | Core I3-13100E | - |
| Intel | Core I3-13100F | - |
| Intel | Core I3-13100T | - |
| Intel | Core I3-13100Te | - |
| Intel | Core I3-1315U | - |
| Intel | Core I3-1315Ue | - |
| Intel | Core I3-1315Ure | - |
| Intel | Core I3-1320Pe | - |
| Intel | Core I3-1320Pre | - |
| Intel | Core I3-13300He | - |
| Intel | Core I3-13300Hre | - |
| Intel | Core I5-1334U | - |
| Intel | Core I5-1335U | - |
| Intel | Core I5-1335Ue | - |
Related Weaknesses (CWE)
References
- https://www.insyde.com/security-pledgeVendor Advisory
- https://www.insyde.com/security-pledge/SA-2023054Vendor Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://www.insyde.com/security-pledge/SA-2023054Vendor Advisory
FAQ
What is CVE-2023-39281?
CVE-2023-39281 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.
How severe is CVE-2023-39281?
CVE-2023-39281 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-39281?
Check the references section above for vendor advisories and patch information. Affected products include: Insyde Insydeh2O, Intel B760, Intel C262, Intel C266, Intel Core I3-1305U.