Description
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
Published: 2026-08-12
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This UEFI vulnerability stems from a failure to perform verified boot on certain firmware volumes, allowing an attacker to inject and execute arbitrary code during system startup. The flaw is classified as CWE‑1277, reflecting improper handling of firmware integrity checks. If exploited, the attacker can gain full control over the system’s firmware environment, compromising confidentiality, integrity, and availability from the very earliest boot stages.

Affected Systems

Affected products include Insyde Software’s InsydeH2O UEFI firmware and a broad set of Intel mobile and server/embedded platforms. For Intel mobile, versions Aarow Lake H/U 05.56.17.0022, Aarow Lake S/HX 05.56.17.0037, Rapter Lake 05.47.24.0058, and Twin Lake 05.44.45.0029 are impacted. On Intel server/embedded, Alder Lake 05.47.24.2057, Raptor Lake 05.47.24.0057, Meteor Lake – U/H ARL‑H/U 05.56.07.0022, Meteor Lake – PS ARL‑H/U 05.56.07.0022, Arrow Lake – S ARL‑S/HX 05.55.45.0036, Arrow Lake – U/H ARL‑H/U 05.56.07.0022, and Elkhart Lake 05.48.17.0030 are vulnerable. Platforms marked as "Trunk" or "Unaffected" are considered not impacted by this issue.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability, but an EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The flaw is not listed in the CISA KEV catalog, which means no known exploits are reported yet. However, the attack vector is inferred to involve manipulating the firmware volumes—either through physical access to the system’s flash storage or by compromising the firmware update process. Once a malicious FV is loaded, the attacker can achieve full privilege escalation at the firmware level, rendering all operating system–based security controls ineffective until the firmware is corrected. The risk is therefore significant for organizations that deploy the affected Intel platforms or InsydeH2O firmware and rely on firmware integrity for critical security functions.

Generated by OpenCVE AI on August 12, 2026 at 14:45 UTC.

Remediation

Vendor Solution

Intel Mobile Platforms: Panther Lake: Unaffected Lunar Lake: Unaffected Aarow Lake H/U: Version 05.56.17.0022 Aarow Lake S/HX: Version 05.56.17.0037 Rapter Lake: Version 05.47.24.0058 Twin Lake: Version 05.44.45.0029   Intel Server/Embedded platforms: Whitley (CLX/CPX/ICX): Trunk CedarIsland (CPX): Trunk Eagle Stream: Unaffected Birch Stream: Unaffected Mehlow/Mehlow-R(CFL-S): Unaffected Tatlow (RKS): Unaffected Jacobsville(SNR): Trunk Idaville: Trunk Kaseyville: Unaffected Whiskey Lake: Trunk Come tLake-S: Unaffected Tiger Lake UP3/H: Unaffected Alder Lake: Version 05.47.24.2057 Raptor Lake: Version 05.47.24.0057 Meteor Lake – U/H ARL-H/U: Version 05.56.07.0022 Meteor Lake – PS ARL-H/U: Version 05.56.07.0022 Arrow Lake – S ARL-S/HX: Version 05.55.45.0036 Arrow Lake – U/H ARL-H/U: Version 05.56.07.0022 Elkhart Lake: Version 05.48.17.0030 Alder Lake N: Trunk Amston Lake: Trunk Twin Lake: Trunk


OpenCVE Recommended Actions

  • Update InsydeH2O firmware to a version that incorporates the verified boot fix, such as the latest public release that supersedes 05.56.17.0037.
  • Patch each affected Intel platform to at least the specified firmware version: 05.47.24.2057 for Alder Lake, 05.47.24.0057 for Raptor Lake, 05.56.07.0022 for Meteor Lake U/H and PS, 05.55.45.0036 for Arrow Lake S, 05.56.07.0022 for Arrow Lake U/H, and 05.48.17.0030 for Elkhart Lake.
  • If immediate patch deployment is not possible, isolate the systems from physical access and disable or remove the vulnerable firmware volumes from the UEFI configuration, then enable secure boot to prevent non‑verified firmware from executing.

Generated by OpenCVE AI on August 12, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Insyde
Insyde insydeh2o
Vendors & Products Insyde
Insyde insydeh2o

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
Title Lack of verified boot to certain FV may cause arbitrary code execution
Weaknesses CWE-1277
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Insyde Insydeh2o
cve-icon MITRE

Status: PUBLISHED

Assigner: Insyde

Published:

Updated: 2026-08-12T12:39:26.057Z

Reserved: 2026-04-17T06:07:36.576Z

Link: CVE-2026-6484

cve-icon Vulnrichment

Updated: 2026-08-12T12:39:23.016Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T01:17:08.060

Modified: 2026-08-31T19:27:23.020

Link: CVE-2026-6484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:56Z

Weaknesses