• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

12 Simple Tweaks to Make Your MacBook’s Battery Last All Day

November 26, 2025

How to Fix Battery Drain, Lag, and Overheating

November 26, 2025

Is Your iPhone Leaking Data? Here’s How to Check Your ‘Browser Fingerprint’

November 25, 2025
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Tech News»Researchers publicly warn that multiple HP firmware vulnerabilities remain unpatched after a year
Tech News

Researchers publicly warn that multiple HP firmware vulnerabilities remain unpatched after a year

September 14, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Researchers publicly warn that multiple HP firmware vulnerabilities remain unpatched after a year
Share
Facebook Twitter LinkedIn Pinterest Email

In short: A number of HP enterprise units are working firmware containing as many as six unpatched safety holes that enable arbitrary code execution. A few of them are at the least a 12 months outdated, and researchers publicly disclosed all of them over a month in the past. As of this writing, all stay unpatched.

On the Black Hat 2022 convention final month, enterprise safety agency Binarly disclosed six tracked vulnerabilities in a number of HP product strains, together with EliteBooks. In a weblog submit final week, it shared the main points to the broader public.

All of the weaknesses concerned a System Administration Mode (SMM) reminiscence corruption that opens the window for arbitrary code execution. These vulnerabilities enable an attacker to implant malware in a tool’s firmware in order that it may persist even after a contemporary set up of the working system. This persistence is why the holes register as excessive threats.

“The impression of focusing on unprivileged non-SMM DXE runtime drivers or functions by a risk actor is commonly underestimated,” stated Binarly. “This type of malicious DXE driver can bypass Safe Boot and affect additional boot levels.”

The six vulnerabilities had been amongst 16 high-severity threats that Binary disclosed on the convention. Builders at HP patched 10 of them, however the remaining are nonetheless large open. Whatsmore, the bugs should not new. Researchers found three in July 2021 and three in April of this 12 months.

Half the issues enable buffer overflows due to inappropriate dealing with of pointers within the CommBuffer. Checks to confirm that the buffer is inside an anticipated vary are lacking. Two others exist due to improper enter validation. Binarly says this oversight permits attackers to achieve management of the CommBuffer and modify it. The final vulnerability is attributable to a scarcity of sanitation within the CommBuffer. Attackers with management of the buffer can create a stack-based overflow resulting in a possibility for arbitrary code execution in SMM.

See also  SK Hynix lowers forecast as fragile economy flattens demand

“Sadly, on the time of writing, some HP enterprise units (laptops and desktops) have nonetheless not acquired updates to patch the aforementioned vulnerabilities, regardless of them being publicly disclosed for over a month,” Binarly notes.

Researchers privately reported all the issues to HP as they found them, however they remained unpatched. So Binarly used Black Hat 2022 to reveal and talk about the weaknesses to warn enterprise admins of the threats.

Since these vulnerabilities are on the firmware degree, full mitigation can solely come from HP. Nonetheless, Binarly has software program out there on GitHub known as FwHunt that may determine if the threats exist in an organization’s infrastructure. Detection will at the least enable directors to isolate and probably comprise susceptible machines.

Source link

Firmware multiple publicly remain researchers unpatched vulnerabilities warn year
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Apple iPhone 17 review: This is the year to upgrade

October 17, 2025

We May Not Get an M5 MacBook Pro This Year After All

July 11, 2025

Apple’s ‘iPhone Fold’ Could Arrive Next Year

July 3, 2025

Apple May Realign iPhone 17 Display Sizes this Year

June 28, 2025
Add A Comment

Comments are closed.

Editors Picks

The iPhone 17 May Get a 120 Hz Display — But Not the One We’re Hoping For

June 4, 2025

How to track Fortnite stats

July 30, 2022

Microsoft might finally simplify its Windows 11 update names

August 23, 2022

Quest v43 Update May Include Long-awaited 16:9 Recording Mode – Road to VR

August 5, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

12 Simple Tweaks to Make Your MacBook’s Battery Last All Day

How to Fix Battery Drain, Lag, and Overheating

Is Your iPhone Leaking Data? Here’s How to Check Your ‘Browser Fingerprint’

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.