Impact
This UEFI vulnerability stems from a failure to perform verified boot on certain firmware volumes, allowing an attacker to inject and execute arbitrary code during system startup. The flaw is classified as CWE‑1277, reflecting improper handling of firmware integrity checks. If exploited, the attacker can gain full control over the system’s firmware environment, compromising confidentiality, integrity, and availability from the very earliest boot stages.
Affected Systems
Affected products include Insyde Software’s InsydeH2O UEFI firmware and a broad set of Intel mobile and server/embedded platforms. For Intel mobile, versions Aarow Lake H/U 05.56.17.0022, Aarow Lake S/HX 05.56.17.0037, Rapter Lake 05.47.24.0058, and Twin Lake 05.44.45.0029 are impacted. On Intel server/embedded, Alder Lake 05.47.24.2057, Raptor Lake 05.47.24.0057, Meteor Lake – U/H ARL‑H/U 05.56.07.0022, Meteor Lake – PS ARL‑H/U 05.56.07.0022, Arrow Lake – S ARL‑S/HX 05.55.45.0036, Arrow Lake – U/H ARL‑H/U 05.56.07.0022, and Elkhart Lake 05.48.17.0030 are vulnerable. Platforms marked as "Trunk" or "Unaffected" are considered not impacted by this issue.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability, but an EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The flaw is not listed in the CISA KEV catalog, which means no known exploits are reported yet. However, the attack vector is inferred to involve manipulating the firmware volumes—either through physical access to the system’s flash storage or by compromising the firmware update process. Once a malicious FV is loaded, the attacker can achieve full privilege escalation at the firmware level, rendering all operating system–based security controls ineffective until the firmware is corrected. The risk is therefore significant for organizations that deploy the affected Intel platforms or InsydeH2O firmware and rely on firmware integrity for critical security functions.
OpenCVE Enrichment