CVE-2023-34195 | Insyde InsydeH2O up to 5.5 SystemFirmwareManagementRuntimeDxe GetImage GetImageProgress code injection
A vulnerability was found in Insyde InsydeH2O up to 5.5. It has been rated as problematic. Affected by this issue is the function GetImage of the component SystemFirmwareManagementRuntimeDxe. The manipulation of the argument GetImageProgress leads to code injection.
This vulnerability is handled as CVE-2023-34195. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.