Severity: HighAction: Patch
VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
Patch
Apply the vendor's security update for the affected products.
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Developments from the last 30 days, newest first.
CVE-2026-12855 scored CVSS 8.2
Basis: NIST National Vulnerability Database
VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
Basis: CERT/CC Vulnerability Notes (CERT advisory)
Apply the vendor's security update for the affected products.