ZeroHour

CVE-2026-33197

mass

Privileged local BIOS code execution in AMI Aptio V (incomplete input validation)

CVSS 4.0
8.7 high
EPSS
<1%p2
Published
()
Modified
AI analysis

AMI's Aptio V UEFI BIOS firmware contains an input-validation flaw classified as CWE-184 (Incomplete List of Disallowed Inputs), meaning a BIOS code path fails to reject all inputs it is supposed to disallow. Triggering it requires local access to the machine, and the CVSS 4.0 metrics show the attacker must already hold high privileges (typically OS-level administrator), with no user interaction needed but elevated attack prerequisites that must be met. Successful exploitation yields arbitrary code execution in the firmware context with high impact on confidentiality, integrity and availability on the affected system and, per the scoring, potentially on subsequent systems - significant for BIOS because firmware-level compromise can persist across OS reinstalls. Any workstation, server or motherboard shipped with AMI Aptio V firmware by an OEM is in scope. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported (EPSS 0.1%); a separate related AMI firmware issue (VU#718077, Secure Boot bypass via a UEFI Shell embedded in SPI flash) is also documented.

What to do: Check your motherboard or system vendor's support page for BIOS updates incorporating the AMI fix, since no affected-version list is provided here and OEMs package Aptio V fixes in their own BIOS releases. Until patched, restrict local administrative access on sensitive systems and treat this as a high-severity firmware fix rather than a routine BIOS update. While updating, also verify whether your system's SPI flash contains the embedded UEFI Shell module highlighted in VU#718077, which can be used to bypass Secure Boot.

Affected
AMI (American Megatrends International) Aptio V (AptioV) UEFI BIOS firmware
Estimated exposure
masson the order of tens of millions of installed systems (OEM boards shipping with AMI Aptio V firmware) — AMI is the dominant independent UEFI BIOS supplier and Aptio V is one of its current-generation firmware lines used by major motherboard and system OEMs, implying millions of shipped systems, though the attack surface is limited to users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.

Weakness
CWE-184
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

CERT/CC details VU#718077: UEFI Shell embedded in SPI flash lets attackers bypass Secure Boot and execute pre-boot code; patches issued.

CERT/CC's VU#718077, reported by Eclypsium researcher Stas Lyakhov, describes how a UEFI Shell embedded in SPI flash can be abused by attackers who can modify UEFI boot configuration, creating multiple boot entries that bypass controls preventing the Shell from launching under Secure Boot. The Shell's dmem and mm commands allow arbitrary physical memory read/write, letting attackers overwrite Secure Boot values and execute unauthorized pre-boot code that can persist across reboots and OS reinstalls while degrading EDR effectiveness. AMI confirmed its Aptio UEFI BDS module is affected (CVE-2026-33197), and Cisco published an advisory for a variation affecting UCS Servers and UCS-based appliances (CVE-2026-20293). Firmware patches are being rolled out through OEM and IBV BIOS build pipelines.