Improper validation vulnerability in Dell InsydeH2O UEFI Firmware - CVE-2021-41840ID: oval:org.secpod.oval:def:77824 | Date: (C)2022-02-18 (M)2023-05-14 |
Class: VULNERABILITY | Family: windows |
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated table variable EFI_BOOT_SERVICES. This allows an attacker who is capable of executing code in DXE phase to exploit this vulnerability to escalate privileges to SMM. The attacker can overwrite the LocateProtocol or Freepool memory address location to execute unwanted code
Platform: |
Microsoft Windows 10 |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows 8.1 |
Microsoft Windows Server 2019 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows 7 |
Microsoft Windows Server |
Microsoft Windows 11 |
Microsoft Windows Server 2022 |