Privilege Escalation in UEFI Firmware for HP PC Products
CVE-2021-39300
8.8HIGH
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 16 February 2022
What is CVE-2021-39300?
Certain HP PC products are susceptible to vulnerabilities in UEFI firmware, which may enable unauthorized privilege escalation and the potential for arbitrary code execution. This flaw poses a significant risk, as it can allow attackers increased control over system functions. Users are encouraged to update their firmware to mitigate these vulnerabilities.
Affected Version(s)
BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS before 01.12.00
BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS before 01.08.00
BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS before 01.19.00