系微安全保證

最新安全公告

INSYDE-SA-2026003

Product

CVSS Score

Original Date

Last Revised

InsydeH2O

8.2

2026-08-11

Summary

Lack of verified boot to certain FV may cause arbitrary code execution.

Vulnerability Details

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

https://www.cve.org/CVERecord?id=CVE-2026-6484

Description: In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

CWE-1277: Insufficient Verification of Data Authenticity in Firmware

Solution Information

Intel Mobile Platforms:
Panther Lake: Unaffected
Lunar Lake: Unaffected
Aarow Lake H/U: Version 05.56.17.0022
Aarow Lake S/HX: Version 05.56.17.0037
Rapter Lake: Version 05.47.24.0058
Twin Lake: Version 05.44.45.0029

 

Intel Server/Embedded platforms:
Whitley (CLX/CPX/ICX): Trunk
CedarIsland (CPX): Trunk
Eagle Stream: Unaffected
Birch Stream: Unaffected
Mehlow/Mehlow-R(CFL-S): Unaffected
Tatlow (RKS): Unaffected
Jacobsville(SNR): Trunk
Idaville: Trunk
Kaseyville: Unaffected
Whiskey Lake: Trunk
Come tLake-S: Unaffected
Tiger Lake UP3/H: Unaffected
Alder Lake: Version 05.47.24.2057
Raptor Lake: Version 05.47.24.0057
Meteor Lake – U/H ARL-H/U: Version 05.56.07.0022
Meteor Lake – PS ARL-H/U: Version 05.56.07.0022
Arrow Lake – S ARL-S/HX: Version 05.55.45.0036
Arrow Lake – U/H ARL-H/U: Version 05.56.07.0022
Elkhart Lake: Version 05.48.17.0030
Alder Lake N: Trunk
Amston Lake: Trunk
Twin Lake: Trunk

Acknowledgements

Thanks to Nikolaj Schlej, independent firmware security researcher, for reporting the vulnerability and engaging in this coordinated disclosure.

Revision History

Revision #

Date

Description

1

2026-08-11

Initial Release