CVE Vulnerabilities

CVE-2020-5953

Published: Feb 03, 2022 | Modified: Nov 04, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).

Affected Software

NameVendorStart VersionEnd Version
Insydeh2oInsyde5.12.09.0074 (including)5.12.09.0074 (including)
Insydeh2oInsyde5.23.04.0045 (including)5.23.04.0045 (including)
Insydeh2oInsyde5.23.45.0023 (including)5.23.45.0023 (including)
Insydeh2oInsyde5.33.15.0034 (including)5.33.15.0034 (including)
Insydeh2oInsyde5.34.03.0029 (including)5.34.03.0029 (including)
Insydeh2oInsyde5.42.03.0010 (including)5.42.03.0010 (including)

References