# HP BIOS SMM flaw enables firmware-level code execution

Published: 2026-10-01 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/093f9776-a7b4-5dea-891c-75ad7440acfb/hp-bios-smm-flaw-enables-firmware-level-code-execution

> An out-of-bounds write in InsydeH2O IHISI firmware on HP PCs lets kernel-privileged attackers achieve arbitrary code execution in SMM, undermining platform security.

CERT/CC published VU#553437 detailing CVE-2026-12855, an out-of-bounds write vulnerability in the H19WMIHandlerSmm module used by HP PC BIOS built on InsydeH2O IHISI firmware (Kernel version 5.5 or earlier). The flaw resides in a custom HP SMM handler that fails to adequately validate parameters supplied via Software System Management Interrupts (SMI), triggered through I/O port 0xB2 with crafted CPU register values.

An attacker who already has OS kernel (ring 0) privileges can exploit this handler to read or write arbitrary physical memory, including System Management RAM (SMRAM), which is normally isolated from the operating system. By corrupting SMM code or data, an attacker could alter subsequent SMM execution, potentially achieving arbitrary code execution within SMM — one of the most privileged execution contexts on x86 platforms, below the OS and hypervisor. This could also enable persistence that survives OS reinstallation, and depending on platform configuration, may affect UEFI firmware update or flash operations, though firmware/ROM modification is not guaranteed as a direct consequence.

This is a local privilege escalation from kernel to SMM, not a remote or unauthenticated vulnerability — exploitation requires existing kernel-level access, making it most relevant as a post-exploitation or implant-persistence vector rather than an initial access vector. There is no indication of in-the-wild exploitation; this is a coordinated disclosure via CERT/CC and Insyde Software, credited to researcher Zhenyu Liu. Defenders should consult HP's security bulletins to determine affected models and apply BIOS/firmware updates once available, and monitor for firmware integrity anomalies on affected HP systems using InsydeH2O IHISI.

## Mentioned in this report

- Vulnerabilities: CVE-2026-12855

## Detection guidance (public sample)

### CHIPSEC Utility Used for SMI, SMRAM or SPI Flash Interaction

ATT&CK: T1542.001

Detects chipsec_util/chipsec_main invocations that trigger SMIs or access SMRAM, physical memory or SPI flash, the primitives needed to probe or abuse SMM handlers. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: CHIPSEC Utility Used for SMI, SMRAM or SPI Flash Interaction
description: Detects execution of the CHIPSEC framework with modules or sub-commands
  that send software SMIs, read or write physical memory or SMRAM, or access SPI flash.
  These are the primitives used to probe or exploit SMM handler flaws such as out-of-bounds
  writes in vendor SMI handlers reachable via I/O port 0xB2. Rare on normal endpoints
  and expected only on firmware research or validation hosts.
tags:
- attack.persistence
- attack.stealth
- attack.t1542.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_tool:
  - Image|endswith:
    - \chipsec_util.exe
    - \chipsec_main.exe
  - CommandLine|contains:
    - chipsec_util
    - chipsec_main
  selection_args:
    CommandLine|contains:
    - ' smi '
    - ' mem '
    - ' spi '
    - smm
    - smram
    - ' io '
    - bios_wp
  condition: selection_tool and selection_args
falsepositives:
- Firmware security researchers or platform validation teams running CHIPSEC on test
  machines
- Hardware compliance audits that run CHIPSEC against managed endpoints
level: medium
id: 56b9a73c-422a-53f3-a5e3-c85d0d92aa86
status: experimental
author: Vorant
references:
- https://kb.cert.org/vuls/id/553437
```

### Kernel Driver Providing Physical Memory or Port I/O Access Installed as a Service

ATT&CK: T1068

Detects installation of known physical-memory/port-I/O kernel drivers that give ring-0 access needed to issue SMIs via port 0xB2 or write SMRAM. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Kernel Driver Providing Physical Memory or Port I/O Access Installed as a Service
description: Detects a new kernel-mode service whose image is a driver known to expose
  arbitrary physical memory and I/O port access (RWEverything, WinRing0, CHIPSEC helper).
  With such a driver, a user-mode attacker can issue crafted software SMIs through
  port 0xB2 or read and write SMRAM, as needed to exploit SMM handler flaws like the
  HP H19WMIHandlerSmm out-of-bounds write. Matches the driver capability class, not
  a campaign-specific artefact.
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1068
- attack.t1542.001
logsource:
  product: windows
  service: system
detection:
  selection:
    Provider_Name: Service Control Manager
    EventID: 7045
  selection_driver:
    ImagePath|contains:
    - chipsec_hlpr
    - RwDrv.sys
    - WinRing0
  condition: selection and selection_driver
falsepositives:
- Hardware monitoring or overclocking utilities that bundle WinRing0
- Firmware engineers using RWEverything or CHIPSEC on lab systems
level: medium
id: 305690c6-944b-5389-9477-96cf052080b0
status: experimental
author: Vorant
references:
- https://kb.cert.org/vuls/id/553437
```

### Insyde Firmware Flash Utility Executed on Windows Host

ATT&CK: T1542.001

Detects execution of Insyde H2O flash utilities that write system firmware from within Windows. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Insyde Firmware Flash Utility Executed on Windows Host
description: Detects execution of InsydeH2O flash tools (H2OFFT, iFlash) from the
  OS. Writing firmware from a running OS is the persistence outcome associated with
  SMM compromise on InsydeH2O IHISI platforms. Outside of planned BIOS update windows
  this should be investigated, and correlated with kernel driver installs.
tags:
- attack.persistence
- attack.t1542.001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
    - \H2OFFT-W.exe
    - \H2OFFT-Wx64.exe
    - \H2OFFT-Wx32.exe
    - \iFlashV.exe
    - \iFlash.exe
  condition: selection
falsepositives:
- Planned BIOS updates deployed by IT or the vendor update utility
- Hardware refurbishment and imaging workflows
level: medium
id: 84ee1b75-0a01-5527-b72f-fb8d355ba50a
status: experimental
author: Vorant
references:
- https://kb.cert.org/vuls/id/553437
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://kb.cert.org/vuls/id/553437

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/093f9776-a7b4-5dea-891c-75ad7440acfb/hp-bios-smm-flaw-enables-firmware-level-code-execution.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
