HP System BIOS Privilege Escalation and Code Execution Vulnerability

Vulnerability

A vulnerability in the System BIOS of certain HP PC products could allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure. This vulnerability requires a physical attack using specialized equipment and knowledge. HP is releasing firmware updates to address this issue.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, execution of arbitrary code, denial of service, or unauthorized information disclosure.

Remediation

HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the vulnerability. Users should check the HP Customer Support - Software and Driver Downloads site for the latest updates for their product model.

Added: Aug 13, 2025, 10:11 PM
Updated: Aug 13, 2025, 10:11 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.