Impact
An unvalidated memory boundary in the H19WMIHandlerSmm module can allow an attacker to execute arbitrary code within the system’s firmware. The flaw exists only in code developed specifically for HP projects inside the InsydeH2O firmware. Abuse of this defect would let a malicious party subvert the confidentiality, integrity, and availability of the entire system, potentially granting full control over the machine.
Affected Systems
The issue affects Insyde Software’s InsydeH2O firmware on HP platforms. Vulnerable firmware versions include Platform 5.4 (05.47.2701.2631), Platform 5.5 (05.55.45.2630), Platform 5.6 (05.62.29.2630), Platform 5.7 (05.72.21.2630), and Platform 6.0 (06.01.23.2630).
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Risk is elevated for systems running the affected firmware because exploitation would require exploitation of the System Management Mode handler. Based on the description, the likely attack vector is a privileged local attacker who can influence firmware execution, possibly through a malicious OS process or during system startup, but the exact exploitation path is not detailed in the advisory.
OpenCVE Enrichment