Executive brief
InsydeH2O is firmware used in HP systems. An unvalidated memory boundary condition in the H19WMIHandlerSmm component could allow a privileged local attacker to execute arbitrary code with high privileges, potentially compromising the entire system including all confidentiality, integrity, and availability of data.
Technical details
This vulnerability is an improper input validation issue (CWE-20) in the H19WMIHandlerSmm component of InsydeH2O firmware. The unvalidated memory boundary condition could result in arbitrary code execution. The attack vector is local with high privilege requirements (PR:H) and no user interaction needed. An attacker with high privileges can exploit this to achieve complete system compromise with high impact to confidentiality, integrity, and availability. Patches are available via HP feature version updates across platforms 5.4 through 6.0.
Affected products
- Insyde InsydeH2O Platform 5.4, 5.5, 5.6, 5.7, 6.0 (prior to patched versions: 05.47.2701.2631, 05.55.45.2630, 05.62.29.2630, 05.72.21.2630, 06.01.23.2630)
Timeline
- 2026-09-08: disclosed
- 2026-09-09: advisory