HP BIOS SMM flaw enables firmware-level code execution
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
An out-of-bounds write in InsydeH2O IHISI firmware on HP PCs lets kernel-privileged attackers achieve arbitrary code execution in SMM, undermining platform security.
CERT/CC published VU#553437 detailing CVE-2026-12855, an out-of-bounds write vulnerability in the H19WMIHandlerSmm module used by HP PC BIOS built on InsydeH2O IHISI firmware (Kernel version 5.5 or earlier). The flaw resides in a custom HP SMM handler that fails to adequately validate parameters supplied via Software System Management Interrupts (SMI), triggered through I/O port 0xB2 with crafted CPU register values.
An attacker who already has OS kernel (ring 0) privileges can exploit this handler to read or write arbitrary physical memory, including System Management RAM (SMRAM), which is normally isolated from the operating system. By corrupting SMM code or data, an attacker could alter subsequent SMM execution, potentially achieving arbitrary code execution within SMM — one of the most privileged execution contexts on x86 platforms, below the OS and hypervisor. This could also enable persistence that survives OS reinstallation, and depending on platform configuration, may affect UEFI firmware update or flash operations, though firmware/ROM modification is not guaranteed as a direct consequence.
This is a local privilege escalation from kernel to SMM, not a remote or unauthenticated vulnerability — exploitation requires existing kernel-level access, making it most relevant as a post-exploitation or implant-persistence vector rather than an initial access vector. There is no indication of in-the-wild exploitation; this is a coordinated disclosure via CERT/CC and Insyde Software, credited to researcher Zhenyu Liu. Defenders should consult HP's security bulletins to determine affected models and apply BIOS/firmware updates once available, and monitor for firmware integrity anomalies on affected HP systems using InsydeH2O IHISI.
Mentioned in this report
Source reporting: https://kb.cert.org/vuls/id/553437
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,554 reports from 152 sources, 494 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs