Privilege Escalation and Code Execution Vulnerabilities in UEFI Firmware by HP
CVE-2021-39299

8.8HIGH

What is CVE-2021-39299?

Multiple vulnerabilities have been found in the UEFI firmware of several HP PC products, potentially allowing attackers to escalate privileges and execute arbitrary code. This breach could lead to unauthorized access and control over the affected systems, posing serious risks to users' data and system integrity. Users are encouraged to apply available patches and updates to mitigate the risk associated with these vulnerabilities.

Affected Version(s)

BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS before 01.12.00

BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS before 01.08.00

BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS before 01.19.00

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.