Junglewise Threat Intelligence

CVE-2021-43614: Insyde InsydeH2O buffer overflow in PlatformLangCodes UEFI variable handling

CVE-2021-43614 · Severity: medium · CVSS 6.7 · Published 2026-09-03

Technologies: InsydeH2O. Vendors: Insyde.

Executive brief

InsydeH2O is firmware used in many systems to manage boot and configuration settings. A buffer overflow vulnerability in how the firmware handles the PlatformLangCodes UEFI variable could allow an attacker with high privileges to crash the system or cause resource exhaustion, resulting in service unavailability. An attacker would need physical or administrative access to the system to exploit this issue.

Technical details

The VariableEditSmm driver in InsydeH2O improperly handles the PlatformLangCodes UEFI variable, leading to a buffer overflow condition. The vulnerability is triggered via improper input validation when processing this variable, and requires high privilege level (PR:H) and user interaction (UI:R) to exploit. The attack vector is physical (AV:P) with high attack complexity (AC:H). Successful exploitation can cause resource exhaustion, system failure, and potential code execution. The vulnerability was fixed in InsydeH2O feature version 01.01.04.0008 and later.

Affected products

  • Insyde InsydeH2O before 01.01.04.0008

Timeline

  • 2022-02-21: disclosed: Initial public disclosure by Insyde
  • 2022-02-21: patched: Fixed in InsydeH2O feature version 01.01.04.0008

References

Related threats