Skip to main content

CISA issues alert on InsydeH2O IHISI SMM unsafe memory writes

55th article in the last 90 days, one of 617 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: National Cybersecurity Alliance Sets 2026 Awareness Month Theme (Oct 2026).

Companies mentioned

Best suited for

Seniority
Analyst
Job function
Cybersecurity / Security Analyst
Persona
Security Operations Practitioner
Buyer role
Technical Implementer / Administrator
Buyer journey
Open to Buy
Adoption curve
Laggards
Technology maturity
Market Correction
Industry
Information Technology / Cybersecurity / Exposure, Risk & Governance / Vulnerability Management & Attack Surface Management

Our classification, not the publisher's statement. Best suited for, not only for.

An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code runs in System Management Mode (SMM), exploitation can enable modification of SMM-protected memory and may result in arbitrary code execution in SMM.

CVE-2026-12855 is an Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) that allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler. The affected system uses InsydeH2O Kernel version 5.5 or earlier. An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation.

Exploitation that modifies SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution in SMM and persistence via modifying SMRAM. The ability to affect firmware or ROM contents is platform-dependent and is not assumed as a direct consequence of this vulnerability.

Users should check HP’s security bulletins to determine whether their system is affected. An Insyde advisory is available at https://www.insyde.com/security-pledge/sa-2026009/.

Thank you to Zhenyu Liu for reporting these vulnerabilities. This document was written by Vijay Sarvepalli.

Blog post, originally published at kb.cert.org.

Structured data (JSON-LD)

The schema.org markup this page publishes for search engines and AI agents, exactly as they read it.

[
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#website",
    "@type": "WebSite",
    "name": "Decision Insights",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://decisioninsights.ai/search/?q={search_term_string}&submit=1"
      }
    },
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    },
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#organization",
    "@type": "Organization",
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer support",
      "email": "[email protected]"
    },
    "description": "Decision Insights is a Registry of technology companies, open source projects, and industry terms, built for people and for AI agents that need sourced, structured information.",
    "logo": {
      "@type": "ImageObject",
      "url": "https://wiretap-cdn-assets.nyc3.cdn.digitaloceanspaces.com/decision-insights/[email protected]"
    },
    "name": "Decision Insights",
    "parentOrganization": {
      "@type": "Organization",
      "name": "Wiretap Labs",
      "sameAs": [
        "https://www.linkedin.com/company/wiretap-labs",
        "https://www.crunchbase.com/organization/wiretap-labs"
      ],
      "url": "https://wiretaplabs.com"
    },
    "publishingPrinciples": "https://decisioninsights.ai/standards/",
    "sameAs": [
      "https://www.linkedin.com/company/decisioninsights"
    ],
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai",
        "name": "Decision Insights",
        "position": 1
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/records/",
        "name": "Records",
        "position": 2
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/cisa-issues-alert-on-insydeh2o-ihisi-smm-unsafe-memory-writes/",
        "name": "CISA issues alert on InsydeH2O IHISI SMM unsafe memory writes",
        "position": 3
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/cisa-issues-alert-on-insydeh2o-ihisi-smm-unsafe-memory-writes/#blogposting",
    "@type": "BlogPosting",
    "about": {
      "@type": "Organization",
      "name": "HP"
    },
    "audience": [
      {
        "@type": "Audience",
        "additionalType": "Seniority",
        "audienceType": "Analyst"
      },
      {
        "@type": "Audience",
        "additionalType": "Job function",
        "audienceType": "Cybersecurity / Security Analyst"
      },
      {
        "@type": "Audience",
        "additionalType": "Persona",
        "audienceType": "Security Operations Practitioner"
      },
      {
        "@type": "Audience",
        "additionalType": "Buyer role",
        "audienceType": "Technical Implementer / Administrator"
      },
      {
        "@type": "Audience",
        "additionalType": "Adoption curve",
        "audienceType": "Laggards"
      },
      {
        "@type": "Audience",
        "additionalType": "Technology maturity",
        "audienceType": "Market Correction"
      },
      {
        "@type": "Audience",
        "additionalType": "Industry",
        "audienceType": "Information Technology / Cybersecurity / Exposure, Risk & Governance / Vulnerability Management & Attack Surface Management"
      }
    ],
    "author": {
      "@id": "https://decisioninsights.ai/author/decision-insights-threat-desk/#person",
      "@type": "Person",
      "name": "Decision Insights Threat Desk",
      "url": "https://decisioninsights.ai/author/decision-insights-threat-desk/"
    },
    "dateModified": "2026-10-01T11:58:37-06:00",
    "datePublished": "2026-10-01T11:58:33-06:00",
    "description": "InsydeH2O IHISI in HP PC BIOS is affected by CVE-2026-12855, enabling arbitrary physical memory writes through an SMI handler in SMM.",
    "headline": "CISA issues alert on InsydeH2O IHISI SMM unsafe memory writes",
    "isBasedOn": {
      "@type": "CreativeWork",
      "sourceOrganization": {
        "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/",
        "name": "Department of Homeland Security"
      },
      "url": "https://kb.cert.org/vuls/id/553437"
    },
    "keywords": [
      "Data",
      "Software",
      "Vulnerabilities"
    ],
    "mainEntityOfPage": {
      "@id": "https://decisioninsights.ai/cisa-issues-alert-on-insydeh2o-ihisi-smm-unsafe-memory-writes/",
      "@type": "WebPage",
      "sdDatePublished": "2026-10-01",
      "sdPublisher": {
        "@id": "https://decisioninsights.ai/#organization"
      }
    },
    "mentions": [
      {
        "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/",
        "name": "Cybersecurity and Infrastructure Security Agency (CISA)"
      }
    ],
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    }
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/author/decision-insights-threat-desk/#person",
    "@type": "Person",
    "description": "CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.",
    "name": "Decision Insights Threat Desk",
    "sameAs": [
      "https://www.linkedin.com/showcase/decisioninsights/"
    ],
    "url": "https://decisioninsights.ai/author/decision-insights-threat-desk/"
  }
]

Is this your company? Get structured data for your own pages