Impact
VariableEditSmm contains an error in the error checking of the PlatformLangCodes UEFI variable. The oversight can trigger a buffer overflow that leads to resource exhaustion and, as noted in the title, the ability to execute arbitrary code within the firmware context. The flaw originates from insufficient bounds checking and can be exploited by an attacker with control over UEFI variable writes, potentially allowing privilege escalation on the target system.
Affected Systems
The vulnerability affects Insyde Software’s InsydeH2O firmware. No specific firmware revision is disclosed, so any installation of InsydeH2O that incorporates the VariableEditSmm component is potentially at risk. Systems using this firmware should check for vendor releases that address the error in PlatformLangCodes handling.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to inject malicious code into the UEFI environment, which typically requires local physical or firmware access. Once the buffer overflow is triggered, an attacker could gain privileged execution during system boot, leading to complete system compromise.
OpenCVE Enrichment