CVE-2019-16284
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- hp/260 g1 dm firmware · hp/280 pro g1 firmware · hp/285 g2 firmware · hp/340 g3 firmware · hp/340 g4 firmware · hp/346 g3 firmware · hp/346 g4 firmware · hp/348 g3 firmware · hp/348 g4 firmware · hp/elite slice firmware · hp/elite x2 1011 g1 firmware · hp/elite x2 1012 g1 firmware · hp/elitebook 1030 g1 firmware · hp/elitebook 1040 g2 firmware · hp/elitebook 720 g1 firmware · hp/elitebook 720 g2 firmware · hp/elitebook 740 g1 firmware · hp/elitebook 740 g2 firmware · hp/elitebook 750 g1 firmware · hp/elitebook 750 g2 firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/rs-en/document/c06456250Vendor Advisory
- https://support.hp.com/rs-en/document/c06456250Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.