CVE-2020-27339

CVE-2020-27339

An issue was discovered in IdeBusDxe in Insyde InsydeH2O 5.x. Code in system management mode calls a function outside of SMRAM in response to a crafted software SMI, aka Inclusion of Functionality from an Untrusted Control Sphere. Modifying the well-known address of this function allows an attacker to gain control of the system with the privileges of system management mode.

Source: CVE-2020-27339

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다