Insyde SMM Vulnerabilities in BIOS Firmware
ID: 3dc4172d-334c-5e63-82e9-44adc5634a28
STIX ID: report--3dc4172d-334c-5e63-82e9-44adc5634a28
Feed Name: NCC Research
A technical write-up documents multiple severe System Management Mode (SMM) vulnerabilities in Insyde H2O BIOS (IHISI, FTBS and BIOS Guard handlers) discovered in leaked Alder Lake BIOS source code; these flaws (insufficient input validation, TOCTOU and confused-deputy issues) can enable SMRAM corruption and powerful write-what-where primitives, potentially allowing persistent bootkits or firmware compromise across many OEM devices. The issues were coordinated with Insyde PSIRT and fixed in an April 10, 2023 release, but affected numerous platforms and required downstream advisories from vendors such as Lenovo and Dell.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
