vulnerability
Aruba AOS-10: CVE-2021-41839: SMM Privilege Escalation Vulnerability in NvmExpressDxe
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:N/C:P/I:P/A:P) | 2022-02-01 | 2025-01-14 | 2025-04-03 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
2022-02-01
Added
2025-01-14
Modified
2025-04-03
Description
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Solution
aruba-aos-10-cve-2021-41839

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.