CVE-2023-40238 | Insyde InsydeH2O BmpDecoderDxe PixelHeight/PixelWidth memory corruption
A vulnerability was found in Insyde InsydeH2O and classified as critical. Affected by this vulnerability is an unknown functionality of the component BmpDecoderDxe. The manipulation of the argument PixelHeight/PixelWidth results in memory corruption.
This vulnerability is cataloged as CVE-2023-40238. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.