Executive brief
InsydeH2O is a UEFI firmware platform used in enterprise and client systems to manage low-level hardware and security settings. A flaw in the SysPasswordDxe driver allows users with local access to extract password hashes from runtime UEFI variables, enabling privilege escalation to administrator level. This could allow an attacker with physical access or existing user privileges to compromise system security controls.
Technical details
The vulnerability is a credential exposure flaw in the SysPasswordDxe driver within Insyde InsydeH2O firmware. User and administrator password hashes are stored in runtime UEFI variables without proper access controls, making them accessible to local processes with user-level privileges. The attack requires local access (no network vector); an attacker who can execute code or interact with the system at user privilege level can read these variables and perform offline hash cracking or replay attacks to gain administrator access. The issue was patched across multiple kernel versions (5.1 through 5.5) with specific updated builds released in February 2022.
Affected products
- Insyde InsydeH2O Kernel 5.1 before 05.17.03, Kernel 5.2 before 05.27.03, Kernel 5.3 before 05.36.03, Kernel 5.4 before 05.43.46, Kernel 5.5 before 05.51.46
Timeline
- 2022-02-21: disclosed: Insyde Security Advisory SA-2022027 published
- 2022-02-21: patched: Fixes released across Kernel 5.1–5.5 product lines