[WID-SEC-2026-2777] Insyde UEFI Firmware (InsydeH2O): Schwachstelle ermöglicht Codeausführung CVSS Base Score 8.2 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff nein Datum 11.08.2026 Stand 12.08.2026 Mitigation ja Betroffene Systeme Betriebssystem BIOS/Firmware Produktbeschreibung InsydeH2O UEFI BIOS ist eine proprietäre, lizenzierte UEFI-BIOS-Firmware, die Intel und AMD basierte Computer unterstützt. Produkte 11.08.2026 Insyde UEFI Firmware Intel Mobile Platforms Insyde UEFI Firmware Intel Server/Embedded Patforms Insyde UEFI Firmware InsydeH2O Angriff Angriff Ein lokaler Angreifer kann eine Schwachstelle in Insyde UEFI Firmware ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A local attacker can exploit a vulnerability in InsydeH2O UEFI firmware to execute arbitrary code, requiring physical access or local OS privileges. The vulnerability has a high CVSS base score of 8.2. The advisory lists affected platforms as Insyde UEFI Firmware for Intel Mobile Platforms and Intel Server/Embedded Platforms, but specific version ranges are not provided in the given text.