Executive brief
InsydeH2O is firmware used in Intel-based systems. A buffer overflow vulnerability in the SMM (System Management Mode) IHISI command handler allows code to overwrite memory without proper size validation, potentially compromising firmware integrity and enabling privilege escalation or system compromise.
Technical details
This is a buffer overflow vulnerability (CWE-787) in the FMTSWriteUseIntelLib SMM IHISI command handler processing FMTS command 0x32. The vulnerable code reads and writes data without validating buffer boundaries, enabling an out-of-bounds write. The attack requires physical access (adjacent/local attack vector) and high privilege context. An attacker with physical or platform management access could overwrite SMM memory, potentially achieving arbitrary code execution in the most privileged processor mode. Patches are available for multiple Intel platform families (WildCat Lake, Panther Lake, Lunar Lake, Arrow Lake, Raptor Lake, and others) as detailed in the Insyde security advisory.
Affected products
- Insyde InsydeH2O Multiple versions across Intel platforms; patches issued for WildCat Lake 05.72.18.0010, Panther Lake 05.72.17.0032, Lunar Lake 05.62.29.0038, Arrow Lake-H/U 05.56.23.0022, Arrow Lake-S/HX 05.56.23.0037, Raptor Lake 05.47.24.0058, Twin Lake 05.44.45.0029
Timeline
- 2026-08-25: disclosed
- 2026-08-26: advisory