系微安全保證
最新安全公告

INSYDE-SA-2026009
Product
CVSS Score
Original Date
Last Revised
InsydeH2O
8.2
2026-09-08
Summary
H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code execution.
Vulnerability Details
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
https://www.cve.org/CVERecord?id=CVE-2026-12855
Description:
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
CWE-20: Improper Input Validation
Solution Information
HP feature version
– Platform 5.4: 05.47.2701.2631
– Platform 5.5: 05.55.45.2630
– Platform 5.6: 05.62.29.2630
– Platform 5.7: 05.72.21.2630
– Platform 6.0: 06.01.23.2630
Acknowledgements
Thanks to Zhenyu Liu, independent firmware security researcher, for reporting the vulnerability and engaging in this coordinated disclosure.
Revision History
Revision #
Date
Description
1
2026-09-08
Initial Release