VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
CERT warns an InsydeH2O SMM flaw in HP BIOS lets kernel attackers write arbitrary memory, including SMRAM.
CERT/CC published VU#553437 for CVE-2026-12855, an out-of-bounds write in the H19WMIHandlerSmm module of InsydeH2O used by HP PC BIOS. A local attacker who already has OS kernel privileges can issue a software SMI on I/O port 0xB2 with crafted registers and read or write arbitrary physical memory, including SMRAM. Because the handler runs in System Management Mode, that primitive may lead to arbitrary SMM code execution and persistence. Systems on InsydeH2O Kernel 5.5 or earlier may be affected; exploitation in the wild is not reported.
- CVE-2026-12855 is an out-of-bounds write in InsydeH2O IHISI SMM code.
- Exploitation requires local OS kernel privileges and a software SMI on port 0xB2.
- The handler can read or write arbitrary physical memory, including SMRAM.
- Affected firmware uses InsydeH2O Kernel 5.5 or earlier on HP PCs.
- No in-the-wild exploitation is reported; HP bulletins list affected systems.
Vulnerabilities mentionedAll →
- CVE-2026-128558.2<1%Memory Boundary Flaw Enables Local Code Execution in HP Project-Specific Codepublished · HP project-specific code (specific affected products/lines not enumerated in the CVE data)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-12855 | Memory Boundary Flaw Enables Local Code Execution in HP Project-Specific Code CVE-2026-12855 is an input-validation defect (CWE-20) in code developed specifically for HP projects, where a memory boundary is not properly validated, allowing arbitrary code execution. It is triggered locally: an attacker who already holds high privileges on the affected system can reach the vulnerable code path with low attack complexity and no user interaction. Successful exploitation yields arbitrary code execution, and the changed-scope metric with high confidentiality, integrity, and availability impacts indicates the attacker's code executes beyond the vulnerable component's original security boundary. Affected are deployments of HP products that include the affected project-specific code, but the advisory data does not enumerate specific product lines, models, or version ranges. There is currently no evidence of exploitation: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. |
Full article456 words · extracted from kb.cert.org · click to collapse
Overview
An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations.
Description
HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system.
CVE-2026-12855: An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler.
An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation.
Because the affected handler executes in SMM, the resulting arbitrary physical memory write can target memory regions that are normally inaccessible to software executing outside SMM, including SMRAM. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution in SMM. The ability to affect firmware or ROM contents is platform-dependent and is not assumed as a direct consequence of this vulnerability.
Impact
An attacker with privileged OS kernel access (ring 0) can exploit the vulnerability by raising Software SMI interrupts through I/O port 0xB2 with crafted CPU register values. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution and persistence via modifying SMRAM.
Solution
Users should check HP's security bulletins to determine whether their system is affected. Insyde advisory is available at https://www.insyde.com/security-pledge/sa-2026009/
Acknowledgements
Thank you to Zhenyu Liu for reporting these vulnerabilities. This document was written by Vijay Sarvepalli.
Vendor Information
553437
Filter by status:
Filter by content: Additional information available
Sort by:
References
Other Information
| CVE IDs: | CVE-2026-12855 |
| API URL: | VINCE JSON | CSAF |
| Date Public: | 2026-10-01 |
| Date First Published: | 2026-10-01 |
| Date Last Updated: | 2026-10-01 14:33 UTC |
| Document Revision: | 1 |