CVE-2022-29277

HIGHCVSS 8.8/10EPSS 0.19%

Last modified

CVE-2022-29277 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley: 05.42.23.0066 Cedar Island: 05.42.11.0021 Eagle Stream: 05.44.25.0052 Greenlow/Greenlow-R(skylake/kabylake): Trunk Mehlow/Mehlow-R (CoffeeLake-S): Trunk Tatlow (RKL-S): Trunk Denverton: 05.10.12.0042 Snow Ridge: Trunk Graneville DE: 05.05.15.0038 Grangeville DE NS: 05.27.26.0023 Bakerville: 05.21.51.0026 Idaville: 05.44.27.0030 Whiskey Lake: Trunk Comet Lake-S: Trunk Tiger Lake H/UP3: 05.43.12.0052 Alder Lake: 05.44.23.0047 Gemini Lake: Not Affected Apollo Lake: Not Affected Elkhart Lake: 05.44.30.0018 AMD ROME: trunk MILAN: 05.36.10.0017 GENOA: 05.52.25.0006 Snowy Owl: Trunk R1000: 05.32.50.0018 R2000: 05.44.30.0005 V2000: Trunk V3000: 05.44.30.0007 Ryzen 5000: 05.44.30.0004 Embedded ROME: Trunk Embedded MILAN: Trunk Hygon Hygon #1/#2: 05.36.26.0016 Hygon #3: 05.44.26.0007 https://www.insyde.com/security-pledge/SA-2022060. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley: 05.42.23.0066 Cedar Island: 05.42.11.0021 Eagle Stream: 05.44.25.0052 Greenlow/Greenlow-R(skylake/kabylake): Trunk Mehlow/Mehlow-R (CoffeeLake-S): Trunk Tatlow (RKL-S): Trunk Denverton: 05.10.12.0042 Snow Ridge: Trunk Graneville DE: 05.05.15.0038 Grangeville DE NS: 05.27.26.0023 Bakerville: 05.21.51.0026 Idaville: 05.44.27.0030 Whiskey Lake: Trunk Comet Lake-S: Trunk Tiger Lake H/UP3: 05.43.12.0052 Alder Lake: 05.44.23.0047 Gemini Lake: Not Affected Apollo Lake: Not Affected Elkhart Lake: 05.44.30.0018 AMD ROME: trunk MILAN: 05.36.10.0017 GENOA: 05.52.25.0006 Snowy Owl: Trunk R1000: 05.32.50.0018 R2000: 05.44.30.0005 V2000: Trunk V3000: 05.44.30.0007 Ryzen 5000: 05.44.30.0004 Embedded ROME: Trunk Embedded MILAN: Trunk Hygon Hygon #1/#2: 05.36.26.0016 Hygon #3: 05.44.26.0007 https://www.insyde.com/security-pledge/SA-2022060

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.19%

9.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AmdGenoa Firmware< 05.52.25.0006
AmdHygon 1 Firmware< 05.36.26.0016
AmdHygon 2 Firmware< 05.36.26.0016
AmdHygon 3 Firmware< 05.44.26.0007
AmdMilan Firmware< 05.36.10.0017
AmdMilan Firmware< 05.36.26.0016
AmdRome Firmware< 05.36.10.0017
AmdRome Firmware< 05.36.26.0016
AmdRyzen 5300g Firmware< 05.44.30.0004
AmdRyzen 5300ge Firmware< 05.44.30.0004
AmdRyzen 5600g Firmware< 05.44.30.0004
AmdRyzen 5600ge Firmware< 05.44.30.0004
AmdRyzen 5600x Firmware< 05.44.30.0004
AmdRyzen 5700g Firmware< 05.44.30.0004
AmdRyzen 5700ge Firmware< 05.44.30.0004
AmdRyzen 5800x Firmware< 05.44.30.0004
AmdRyzen 5800x3d Firmware< 05.44.30.0004
AmdRyzen 5900x Firmware< 05.44.30.0004
AmdRyzen 5950x Firmware< 05.44.30.0004
AmdSnowy Owl R1000 Firmware< 05.32.50.0018
AmdSnowy Owl R2000 Firmware< 05.44.30.0005
AmdSnowy Owl V2000 Firmware< 05.44.30.0007
AmdSnowy Owl V3000 Firmware< 05.44.30.0007
IntelAlder Lake Firmware< 05.44.23.0047
IntelBakerville Firmware< 05.21.51.0026
IntelCedar Island Firmware< 05.42.11.0021
IntelIdaville Firmware< 05.43.12.0052
IntelComet Lake-S Firmware< 05.43.12.0052
IntelTiger Lake H\/Up3 Firmware< 05.43.12.0052
IntelWhiskey Lake Firmware< 05.43.12.0052
IntelDenverton Firmware< 05.10.12.0042
IntelEagle Stream Firmware< 05.44.25.0052
IntelGrangeville De Ns Firmware< 05.27.26.0023
IntelGranville De Firmware< 05.05.15.0038
IntelGreenlow Firmware< 05.10.12.0042
IntelGreenlow-R Firmware< 05.10.12.0042
IntelMehlow Firmware< 05.10.12.0042
IntelMehlow-R Firmware< 05.10.12.0042
IntelTatlow Firmware< 05.10.12.0042
IntelPurley-R Firmware< 05.21.51.0048
IntelWhitley Firmware< 05.42.23.0066

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-29277?
Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley: 05.42.23.0066 Cedar Island: 05.42.11.0021 Eagle Stream: 05.44.25.0052 Greenlow/Greenlow-R(skylake/kabylake): Trunk Mehlow/Mehlow-R (CoffeeLake-S): Trunk Tatlow (RKL-S): Trunk Denverton: 05.10.12.0042 Snow Ridge: Trunk Graneville DE: 05.05.15.0038 Grangeville DE NS: 05.27.26.0023 Bakerville: 05.21.51.0026 Idaville: 05.44.27.0030 Whiskey Lake: Trunk Comet Lake-S: Trunk Tiger Lake H/UP3: 05.43.12.0052 Alder Lake: 05.44.23.0047 Gemini Lake: Not Affected Apollo Lake: Not Affected Elkhart Lake: 05.44.30.0018 AMD ROME: trunk MILAN: 05.36.10.0017 GENOA: 05.52.25.0006 Snowy Owl: Trunk R1000: 05.32.50.0018 R2000: 05.44.30.0005 V2000: Trunk V3000: 05.44.30.0007 Ryzen 5000: 05.44.30.0004 Embedded ROME: Trunk Embedded MILAN: Trunk Hygon Hygon #1/#2: 05.36.26.0016 Hygon #3: 05.44.26.0007 https://www.insyde.com/security-pledge/SA-2022060
How severe is CVE-2022-29277?
CVE-2022-29277 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2022-29277?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-29277?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST