Arbitrary Code Execution Vulnerability in UEFI Firmware by Insyde Software
CVE-2026-6484
8.2HIGH
What is CVE-2026-6484?
The UEFI firmware developed by Insyde Software is susceptible to a security vulnerability that allows for arbitrary code execution. This issue arises due to the absence of verified boot processes for certain firmware volumes (FVs). If exploited, this flaw may enable malicious actors to execute unauthorized code, potentially compromising the system's integrity and security.
Affected Version(s)
InsydeH2O x86 See in the Solution
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks to Nikolaj Schlej, independent firmware security researcher, for reporting the vulnerability and engaging in this coordinated disclosure.
