InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
What happened
VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations, CERT/CC Vulnerability Notes announced. Overview An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM.
Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations. Description HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system operates with InsydeH2O Kernel version 5.5 or earlier.
Key facts
- The affected system โ uses: InsydeH2O Kernel version 5.5 or earlier
Sources & evidence
- CERT/CC Vulnerability Notes Primary / official
VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations โ
https://kb.cert.org/vuls/id/553437