CISA issues alert on InsydeH2O IHISI SMM unsafe memory writes
55th article in the last 90 days, one of 617 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: National Cybersecurity Alliance Sets 2026 Awareness Month Theme (Oct 2026).
Companies mentioned
Best suited for
- Seniority
- Analyst
- Job function
- Cybersecurity / Security Analyst
- Persona
- Security Operations Practitioner
- Buyer role
- Technical Implementer / Administrator
- Buyer journey
- Open to Buy
- Adoption curve
- Laggards
- Technology maturity
- Market Correction
- Industry
- Information Technology / Cybersecurity / Exposure, Risk & Governance / Vulnerability Management & Attack Surface Management
Our classification, not the publisher's statement. Best suited for, not only for.
An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code runs in System Management Mode (SMM), exploitation can enable modification of SMM-protected memory and may result in arbitrary code execution in SMM.
CVE-2026-12855 is an Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) that allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler. The affected system uses InsydeH2O Kernel version 5.5 or earlier. An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation.
Exploitation that modifies SMM code or data may allow an attacker to alter subsequent SMM execution and potentially achieve arbitrary code execution in SMM and persistence via modifying SMRAM. The ability to affect firmware or ROM contents is platform-dependent and is not assumed as a direct consequence of this vulnerability.
Users should check HP’s security bulletins to determine whether their system is affected. An Insyde advisory is available at https://www.insyde.com/security-pledge/sa-2026009/.
Thank you to Zhenyu Liu for reporting these vulnerabilities. This document was written by Vijay Sarvepalli.
Blog post, originally published at kb.cert.org.