CVE-2023-34195 | Insyde InsydeH2O up to 5.5 SystemFirmwareManagementRuntimeDxe GetImage GetImageProgress code injection (EUVD-2023-38294)
A vulnerability has been found in Insyde InsydeH2O up to 5.5 and classified as critical. Impacted is the function GetImage of the component SystemFirmwareManagementRuntimeDxe. This manipulation of the argument GetImageProgress causes code injection.
This vulnerability appears as CVE-2023-34195. It is feasible to perform the attack on the physical device. There is no available exploit.
The affected component should be upgraded.