Monday, July 20, 2026
HomeCyber SecurityNew 16 Excessive-Severity UEFI Firmware Flaws Found in Tens of millions of...

New 16 Excessive-Severity UEFI Firmware Flaws Found in Tens of millions of HP Units

[ad_1]

New 16 Excessive-Severity UEFI Firmware Flaws Found in Tens of millions of HP Units

Cybersecurity researchers on Tuesday disclosed 16 new high-severity vulnerabilities in numerous implementations of Unified Extensible Firmware Interface (UEFI) firmware impacting a number of HP enterprise gadgets.

The shortcomings, which have CVSS scores starting from 7.5 to eight.8, have been uncovered in HP’s UEFI firmware. The number of gadgets affected consists of HP’s laptops, desktops, point-of-sale (PoS) programs, and edge computing nodes.

“By exploiting the vulnerabilities disclosed, attackers can leverage them to carry out privileged code execution in firmware, beneath the working system, and doubtlessly ship persistent malicious code that survives working system re-installations and permits the bypass of endpoint safety options (EDR/AV), Safe Boot and Virtualization-Primarily based Safety isolation,” firmware safety agency Binarly stated in a report shared with The Hacker Information.

Automatic GitHub Backups

Essentially the most extreme of the failings concern numerous reminiscence corruption vulnerabilities within the System Administration Mode (SMM) of the firmware, thereby enabling the execution of arbitrary code with the very best privileges.

UEFI Firmware

Following a coordinated disclosure course of with HP and CERT Coordination Heart (CERT/CC), the problems had been addressed as a part of a collection of safety updates shipped in February and March 2022.

“Sadly, a lot of the points […] are repeatable failures, a few of that are because of the complexity of the codebase or legacy elements that get much less safety consideration, however are nonetheless extensively used within the area,” the researchers identified.

The disclosure arrives a little bit over a month after Binarly publicized the invention of 23 high-impact vulnerabilities in Insyde Software program’s InsydeH2O UEFI firmware that might be weaponized to deploy persistent malware that is able to evading safety programs.

Prevent Data Breaches

The most recent findings are additionally important in mild of the truth that firmware has emerged as an ever-expanding assault floor for menace actors to launch highly-targeted devastating assaults. At the very least 5 totally different firmware malware strains have been detected within the wild up to now since 2018.

“Securing the firmware layer is commonly ignored, however it’s a single level of failure in gadgets and is likely one of the stealthiest strategies wherein an attacker can compromise gadgets at scale,” the U.S. Commerce and Homeland Safety departments highlighted in a report revealed final month.



[ad_2]

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments