CRITICAL🇬🇧 English

CVE-2023-39281

Stack buffer overflow w AsfSecureBootDxe (InsydeH2O) — RCE w fazie DXE

CVSS 9.8v3.1pub. 2023-11-01upd. 2024-11-21

Krytyczna podatność typu stack buffer overflow w komponencie AsfSecureBootDxe oprogramowania układowego InsydeH2O firmy Insyde umożliwia atakującemu wykonanie dowolnego kodu podczas fazy DXE (Driver Execution Environment). Zagrożenie jest szczególnie poważne, ponieważ eksploatacja następuje na wczesnym etapie uruchamiania systemu, przed załadowaniem systemu operacyjnego.

Pokaż oryginał (EN)

A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

🤖 Analiza AI
Jak działa

Podatność polega na przepełnieniu bufora na stosie (stack buffer overflow, CWE-121/CWE-787) w module AsfSecureBootDxe, który jest częścią firmware'u UEFI InsydeH2O. Podczas fazy DXE — etapu inicjalizacji sprzętu przed uruchomieniem systemu operacyjnego — atakujący może dostarczyć złośliwe dane powodujące zapis poza granice zarezerwowanego bufora na stosie. Pozwala to na nadpisanie krytycznych struktur kontrolnych i przejęcie przepływu wykonania kodu na poziomie firmware'u.

Skutki

Atakujący może wykonać dowolny kod (RCE) w środowisku DXE z pełnymi uprawnieniami firmware'u UEFI, co potencjalnie umożliwia trwałą kompromitację urządzenia poniżej poziomu systemu operacyjnego — w sposób trudny do wykrycia i usunięcia przez standardowe narzędzia bezpieczeństwa.

Mitygacja

Należy zastosować patche dostępne u producenta zgodnie z referencjami — szczegóły w Security Advisory SA-2023054 opublikowanym przez Insyde Software (https://www.insyde.com/security-pledge/SA-2023054). Zaleca się pilną aktualizację firmware'u UEFI do wersji niezawierającej podatności.

Kogo dotyczy

Insyde InsydeH2O z kernelem w wersjach 5.0 do 5.5, stosowany m.in. na platformach Intel B760, Intel C262, Intel C266 oraz procesorach Intel Core i3-1305U.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Insyde Insydeh2o

    APP
    Insyde
    05.45.24.0039
  • Intel B760

    HW
    Intel
    wszystkie wersje
  • Intel C262

    HW
    Intel
    wszystkie wersje
  • Intel C266

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 1305u

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13100

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13100e

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13100f

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13100t

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13100te

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 1315u

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 1315ue

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 1315ure

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 1320pe

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 1320pre

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13300he

    HW
    Intel
    wszystkie wersje
  • Intel Core I3 13300hre

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1334u

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1335u

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1335ue

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 13400

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 13400e

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 13400f

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 13400t

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1340p

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1340pe

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 13420h

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 13450hx

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1345u

    HW
    Intel
    wszystkie wersje
  • Intel Core I5 1345ue

    HW
    Intel
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEMemory
CWE
Referencje

Powiązane podatności

CVE-2021-41842CRITICAL9.8PL ✓ten sam produkt

RCE w Insyde InsydeH2O — brak weryfikacji CommBuffer w SMI handler

CVE-2024-55567HIGH7.5ten sam produkt

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 bef...

CVE-2024-52877HIGH7.5ten sam produkt

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.3...

CVE-2024-52878HIGH7.5ten sam produkt

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.3...

CVE-2024-52879HIGH7.5ten sam produkt

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.3...