{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/553437#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nAn Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations.\r\n\r\n### Description\r\nHP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system.\r\n\r\n**CVE-2026-12855**:  An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler.\r\n\r\nAn attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port `0xB2` and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation.\r\n\r\nBecause the affected handler executes in SMM, the resulting arbitrary physical memory write can target memory regions that are normally inaccessible to software executing outside SMM, including SMRAM. Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution in SMM. The ability to affect firmware or ROM contents is platform-dependent and is not assumed as a direct consequence of this vulnerability.\r\n\r\n### Impact\r\n\r\nAn attacker with privileged OS kernel access (ring 0) can exploit the vulnerability by raising Software SMI interrupts through I/O port `0xB2` with crafted CPU register values.  Modifying SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution and persistence via modifying SMRAM. \r\n\r\n### Solution\r\n\r\nUsers should check [HP's security bulletins](https://support.hp.com/us-en/security-bulletins) to determine whether their system is affected. Insyde advisory is available at [https://www.insyde.com/security-pledge/sa-2026009/](https://www.insyde.com/security-pledge/sa-2026009/)\r\n\r\n### Acknowledgements\r\n\r\nThank you to Zhenyu Liu for reporting these vulnerabilities. This document was written by Vijay Sarvepalli.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"},{"category":"other","text":"Regarding the vulnerability VU#553437, we have completed the technical assessment for our Motherboard and Laptop product lines. We have determined that our products are NOT affected.\r\n\r\nAnalysis Summary:\r\n\r\nVendor-Specific Implementation: The vulnerabilities are located in the OFCSmmDriver (GUID: dbfab6c3-6c4b-4e4f-a8fe-ad1c27d5e8ba) and H19WMIHandlerSmm (GUID: f1946499-571b-44c3-9b9c-cc55210b0c02) modules. These are explicitly identified as HP-custom modules and are not part of the Insyde base core.\r\nSpecific Hardware Scope: The impact is strictly limited to HP system board ID: 8D41 (and sibling 08D42) running BIOS family/version F.22 on the Intel Meteor Lake SoC.\r\nRoot Cause: The issue stems from a failure to perform memory range validation (missing SmmIsBufferOutsideSmmValid or TSEG checks) within HP's custom SMM handlers when processing Software SMIs (specifically SW SMI 0xB2).\r\nSince our Motherboard and Laptop product lines do not utilize these HP-proprietary custom modules or the specific affected hardware IDs, there is no risk to our platforms.","title":"Vendor statment from GIGABYTE"},{"category":"other","text":"ASUS is not affected by the vulnerabilities described in this report, as the compromised modules are specific to another vendor's customization and are not present in ASUS products.","title":"Vendor statment from ASUSTeK Computer Inc."},{"category":"other","text":"The vulnerable modules are OEM specific developed by Insyde. They do not exist in the standard Insyde code released to downstream developers.","title":"Vendor statment from Insyde Software Corporation"},{"category":"other","text":"Vulnerable code is not present in AMI products.","title":"Vendor statment from American Megatrends Incorporated (AMI)"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/553437"},{"url":"https://www.microsoft.com/en-us/security/blog/2020/11/12/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform/","summary":"https://www.microsoft.com/en-us/security/blog/2020/11/12/system-management-mode-deep-dive-how-smm-isolation-hardens-the-platform/"},{"url":"https://support.hp.com/us-en/security-bulletins","summary":"https://support.hp.com/us-en/security-bulletins"},{"url":"https://www.insyde.com/security-pledge/sa-2026009/","summary":"https://www.insyde.com/security-pledge/sa-2026009/"}],"title":"InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations","tracking":{"current_release_date":"2026-10-01T14:33:19+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.49"}},"id":"VU#553437","initial_release_date":"2026-10-01 14:33:19.071497+00:00","revision_history":[{"date":"2026-10-01T14:33:19+00:00","number":"1.20261001143319.1","summary":"Released on 2026-10-01T14:33:19+00:00"}],"status":"final","version":"1.20261001143319.1"}},"vulnerabilities":[{"title":"InsideH2O IHISI SMM software is vulnerable to arbitrary memory read and write using an attacker-controlled pointer taken from the SMI save-state.","notes":[{"category":"summary","text":"InsideH2O IHISI SMM software is vulnerable to arbitrary memory read and write using an attacker-controlled pointer taken from the SMI save-state. As the pointer is not validated against SMRAM (no SmmIsBufferOutsideSmmValid / TSEG range check), violating the SMM\r\ntrust boundary. An attacker can use this unsafe memory operations to access sensitive memory and infect SMRAM providing persistence below the operating system into UEFI environment."}],"cve":"CVE-2026-12855","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#553437"}],"product_status":{"known_affected":["CSAFPID-ff9cc2e8-bdb6-11f1-ab8d-12ffe47dc9c7"],"known_not_affected":["CSAFPID-ff9c14ec-bdb6-11f1-ab8d-12ffe47dc9c7","CSAFPID-ff9c41f6-bdb6-11f1-ab8d-12ffe47dc9c7","CSAFPID-ff9c7216-bdb6-11f1-ab8d-12ffe47dc9c7","CSAFPID-ff9c9bb0-bdb6-11f1-ab8d-12ffe47dc9c7","CSAFPID-ff9ce8fe-bdb6-11f1-ab8d-12ffe47dc9c7"]}}],"product_tree":{"branches":[{"category":"vendor","name":"GIGABYTE","product":{"name":"GIGABYTE Products","product_id":"CSAFPID-ff9c14ec-bdb6-11f1-ab8d-12ffe47dc9c7"}},{"category":"vendor","name":"ASUSTeK Computer Inc.","product":{"name":"ASUSTeK Computer Inc. Products","product_id":"CSAFPID-ff9c41f6-bdb6-11f1-ab8d-12ffe47dc9c7"}},{"category":"vendor","name":"Intel","product":{"name":"Intel Products","product_id":"CSAFPID-ff9c7216-bdb6-11f1-ab8d-12ffe47dc9c7"}},{"category":"vendor","name":"Phoenix Technologies","product":{"name":"Phoenix Technologies Products","product_id":"CSAFPID-ff9c9bb0-bdb6-11f1-ab8d-12ffe47dc9c7"}},{"category":"vendor","name":"Insyde Software Corporation","product":{"name":"Insyde Software Corporation Products","product_id":"CSAFPID-ff9cc2e8-bdb6-11f1-ab8d-12ffe47dc9c7"}},{"category":"vendor","name":"American Megatrends Incorporated (AMI)","product":{"name":"American Megatrends Incorporated (AMI) Products","product_id":"CSAFPID-ff9ce8fe-bdb6-11f1-ab8d-12ffe47dc9c7"}}]}}