HP System BIOS Privilege Escalation and Code Execution Vulnerability
Vulnerability
A vulnerability in the System BIOS of certain HP PC products could allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure. This vulnerability requires a physical attack using specialized equipment and knowledge. HP is releasing firmware updates to address this issue.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, execution of arbitrary code, denial of service, or unauthorized information disclosure.
Remediation
HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the vulnerability. Users should check the HP Customer Support - Software and Driver Downloads site for the latest updates for their product model.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
