Impact
The FMTSWriteUseIntelLib routine in the SMM IHISI command handler processes FMTS command 0x32 without checking the size of data it reads or writes. This omission can overflow an internal buffer, corrupting adjacent memory and potentially compromising firmware integrity or causing a crash. The flaw resides entirely in privileged firmware code, and the CVSS score of 2.7 indicates limited impact under most conditions.
Affected Systems
InsydeH2O firmware installed on Intel‑based laptops, servers, and embedded devices is affected. The vulnerability requires firmware‑level privileged execution. The vendor’s official fix comprises Intel firmware updates – for mobile platforms use the specific version numbers listed (for example WildCat Lake 05.72.18.0010, Panther Lake 05.72.17.0032, Luna Lake 05.62.29.0038, etc.), and for server/embedded platforms update to the latest trunk firmware from Intel. Users should verify their device’s firmware platform and apply the corresponding Intel update described in Intel’s Mobile or Server/Embedded update catalog.
Risk and Exploitability
The CVSS score of 2.7 and the absence of an EPSS rating indicate a low‑severity flaw, and it is not listed in the CISA KEV catalog. Exploitation would require local or privileged access to the device to invoke the vulnerable firmware command, typically via the firmware update interface or another privileged tool. Under these constraints the threat is modest, but applying the available firmware update is strongly recommended to eliminate the risk of buffer corruption.
OpenCVE Enrichment