{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-12855","assignerOrgId":"8338d8cb-57f7-4252-abc0-96fd13e98d21","state":"PUBLISHED","assignerShortName":"Insyde","dateReserved":"2026-06-22T05:49:02.853Z","datePublished":"2026-09-09T03:59:11.348Z","dateUpdated":"2026-10-01T15:08:22.356Z"},"containers":{"cna":{"providerMetadata":{"orgId":"8338d8cb-57f7-4252-abc0-96fd13e98d21","shortName":"Insyde","dateUpdated":"2026-09-09T03:59:11.348Z"},"title":"H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code execution.","datePublic":"2026-09-09T03:56:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-20","description":"CWE-20: Improper Input Validation","type":"CWE"}]}],"affected":[{"vendor":"Insyde Software","product":"InsydeH2O","platforms":["x86"],"versions":[{"status":"affected","version":"See in the Solution"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.","supportingMedia":[{"type":"text/html","base64":false,"value":"Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects."}]}],"references":[{"url":"https://www.insyde.com/security-pledge/sa-2026009/"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":8.2,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"HP feature version\n– Platform 5.4: 05.47.2701.2631\n– Platform 5.5: 05.55.45.2630\n– Platform 5.6: 05.62.29.2630\n– Platform 5.7: 05.72.21.2630\n– Platform 6.0: 06.01.23.2630","supportingMedia":[{"type":"text/html","base64":false,"value":"HP feature version<br>– Platform 5.4: 05.47.2701.2631<br>– Platform 5.5: 05.55.45.2630<br>– Platform 5.6: 05.62.29.2630<br>– Platform 5.7: 05.72.21.2630<br>– Platform 6.0: 06.01.23.2630"}]}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-12855","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-09-09T15:54:34.074995Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-09T20:51:33.091Z"}},{"title":"CVE Program Container","references":[{"url":"https://www.kb.cert.org/vuls/id/553437"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-10-01T15:08:22.356Z"}}]}}