Vulnerabilities in UEFI firmware based on the InsydeH2O framework allow code execution at the SMM level.
In the InsydeH2O framework, used by many manufacturers to create UEFI firmware for their hardware (the most common implementation of UEFI BIOS), 23 vulnerabilities have been discovered that allow code execution at the SMM (System Management Mode) level, which is more privileged (Ring -2) than hypervisor mode and the zero protection ring, and has unrestricted access to all memory. The issue affects UEFI firmware used by manufacturers such as Fujitsu, […]
