CVE-2023-39281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
01/11/2023
Last modified:
06/09/2024

Description

A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:intel:b760:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:c262:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:c266:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-1305u:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-13100:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-13100e:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-13100f:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-13100t:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-13100te:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-1315u:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-1315ue:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-1315ure:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-1320pe:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-1320pre:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:core_i3-13300he:-:*:*:*:*:*:*:*