search menu icon-carat-right cmu-wordmark

CERT Coordination Center

InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations

Vulnerability Note VU#553437

Original Release Date: 2026-10-01 | Last Revised: 2026-10-01

Overview

An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations.

Description

HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system.

CVE-2026-12855: An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler.

An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation.

Because the affected handler executes in SMM, the resulting arbitrary physical memory write can target memory regions that are normally inaccessible to software executing outside SMM, including SMRAM. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution in SMM. The ability to affect firmware or ROM contents is platform-dependent and is not assumed as a direct consequence of this vulnerability.

Impact

An attacker with privileged OS kernel access (ring 0) can exploit the vulnerability by raising Software SMI interrupts through I/O port 0xB2 with crafted CPU register values. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution and persistence via modifying SMRAM.

Solution

Users should check HP's security bulletins to determine whether their system is affected. Insyde advisory is available at https://www.insyde.com/security-pledge/sa-2026009/

Acknowledgements

Thank you to Zhenyu Liu for reporting these vulnerabilities. This document was written by Vijay Sarvepalli.

Vendor Information

553437
 

Insyde Software Corporation Affected

Notified:  2026-06-17 Updated: 2026-10-01

Statement Date:   July 27, 2026

CVE-2026-12855 Affected

Vendor Statement

The vulnerable modules are OEM specific developed by Insyde. They do not exist in the standard Insyde code released to downstream developers.

American Megatrends Incorporated (AMI) Not Affected

Notified:  2026-06-17 Updated: 2026-10-01

Statement Date:   August 24, 2026

CVE-2026-12855 Not Affected

Vendor Statement

Vulnerable code is not present in AMI products.

ASUSTeK Computer Inc. Not Affected

Notified:  2026-06-17 Updated: 2026-10-01

Statement Date:   June 22, 2026

CVE-2026-12855 Not Affected

Vendor Statement

ASUS is not affected by the vulnerabilities described in this report, as the compromised modules are specific to another vendor's customization and are not present in ASUS products.

GIGABYTE Not Affected

Notified:  2026-06-17 Updated: 2026-10-01

Statement Date:   June 18, 2026

CVE-2026-12855 Not Affected

Vendor Statement

Regarding the vulnerability VU#553437, we have completed the technical assessment for our Motherboard and Laptop product lines. We have determined that our products are NOT affected.

Analysis Summary:

Vendor-Specific Implementation: The vulnerabilities are located in the OFCSmmDriver (GUID: dbfab6c3-6c4b-4e4f-a8fe-ad1c27d5e8ba) and H19WMIHandlerSmm (GUID: f1946499-571b-44c3-9b9c-cc55210b0c02) modules. These are explicitly identified as HP-custom modules and are not part of the Insyde base core.
Specific Hardware Scope: The impact is strictly limited to HP system board ID: 8D41 (and sibling 08D42) running BIOS family/version F.22 on the Intel Meteor Lake SoC.
Root Cause: The issue stems from a failure to perform memory range validation (missing SmmIsBufferOutsideSmmValid or TSEG checks) within HP's custom SMM handlers when processing Software SMIs (specifically SW SMI 0xB2).
Since our Motherboard and Laptop product lines do not utilize these HP-proprietary custom modules or the specific affected hardware IDs, there is no risk to our platforms.

Intel Not Affected

Notified:  2026-06-17 Updated: 2026-10-01

Statement Date:   June 22, 2026

CVE-2026-12855 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Phoenix Technologies Not Affected

Notified:  2026-06-17 Updated: 2026-10-01

Statement Date:   June 23, 2026

CVE-2026-12855 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Acer Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Amazon Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Aruba Networks Unknown

Notified:  2026-07-06 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Dell Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fujitsu HQ Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

GETAC Inc. Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Google Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Hewlett Packard Enterprise Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

HP Inc. Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lenovo Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Microsoft Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Supermicro Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

Toshiba Corporation Unknown

Notified:  2026-06-17 Updated: 2026-10-01

CVE-2026-12855 Unknown

Vendor Statement

We have not received a statement from the vendor.

View all 19 vendors View less vendors


Other Information

CVE IDs: CVE-2026-12855
API URL: VINCE JSON | CSAF
Date Public: 2026-10-01
Date First Published: 2026-10-01
Date Last Updated: 2026-10-01 14:33 UTC
Document Revision: 1

Sponsored by CISA.