ZeroHour

CVE-2019-16284

CVSS 3.1
7.2 high
EPSS
2%p79
Published
()
Modified
Description

A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.

Vendors
hp
Products
260 g1 dm firmware, 280 pro g1 firmware, 285 g2 firmware, 340 g3 firmware, 340 g4 firmware, 346 g3 firmware, 346 g4 firmware, 348 g3 firmware, 348 g4 firmware, elite slice firmware, elite x2 1011 g1 firmware, elite x2 1012 g1 firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.