Junglewise Threat Intelligence

CVE-2026-33197: AMI APTIOV input validation vulnerability in BIOS

CVE-2026-33197 · Severity: info · Published 2026-09-08

Executive brief

AMI APTIOV is firmware used in enterprise server BIOS. A privileged local user can exploit an input validation weakness to achieve arbitrary code execution, potentially compromising the confidentiality, integrity, and availability of the system and any data it processes.

Technical details

The vulnerability is an incomplete list of disallowed inputs (input validation weakness) in the BIOS component of AMI APTIOV firmware. It requires local access and elevated privileges to exploit. Successful exploitation allows an attacker to execute arbitrary code, affecting the entire system. The vulnerability was reported with info severity, though the stated impact suggests higher risk (arbitrary code execution affecting CIA triad). Patch availability has not been confirmed in the advisory text.

Affected products

  • AMI APTIOV

Timeline

  • 2026-09-08: disclosed

References