A vulnerability classified as critical was found in Insyde InsydeH2O. Affected by this vulnerability is an unknown functionality of the component BmpDecoderDxe. The manipulation of the argument PixelHeight/PixelWidth leads to memory corruption.

This vulnerability is known as CVE-2023-40238. Access to the local network is required for this attack. There is no exploit available.

It is recommended to upgrade the affected component.