7.2
CVSSv3

CVE-2019-16284

Published: 05/11/2019 Updated: 24/08/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an malicious user to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in support.hp.com/rs-en/document/c06456250.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hp 260_g1_dm_firmware

hp 280_pro_g1_firmware

hp 285_g2_firmware

hp 340_g3_firmware

hp 340_g4_firmware

hp 346_g3_firmware

hp 346_g4_firmware

hp 348_g3_firmware

hp 348_g4_firmware

hp elite_slice_firmware

hp elite_x2_1011_g1_firmware

hp elite_x2_1012_g1_firmware

hp elitebook_1030_g1_firmware

hp elitebook_1040_g2_firmware

hp elitebook_720_g1__firmware

hp elitebook_720_g2_firmware

hp elitebook_740_g1_firmware

hp elitebook_740_g2_firmware

hp elitebook_750_g1_firmware

hp elitebook_750_g2_firmware

hp elitebook_820_g1_firmware

hp elitebook_820_g2_firmware

hp elitebook_820_g3_firmware

hp elitebook_828_g3_firmware

hp elitebook_840_g1_firmware

hp elitebook_840_g2_firmware

hp elitebook_840_g3_firmware

hp elitebook_848_g3_firmware

hp elitebook_850_g1_firmware

hp elitebook_850_g2_firmware

hp elitebook_850_g3_firmware

hp elitebook_folio_1020_g1_firmware

hp elitebook_folio_1040_g1_firmware

hp elitebook_folio_1040_g3_firmware

hp elitebook_folio_9480m_firmware

hp elitebook_folio_g1_firmware

hp elitebook_revolve_810_g2_firmware

hp elitebook_revolve_810_g3_firmware

hp elitedesk_800_g2_dm_firmware

hp elitedesk_800_g2_sff_firmware

hp elitedesk_800_g2_twr_firmware

hp eliteone_800_g2_aio_firmware

hp elitepad_1000_g2_firmware

hp mp9_g2_retail_system_firmware

hp pro_tablet_10_ee_g1_firmware

hp pro_tablet_608_g1_firmware

hp pro_tablet_610_g1_firmware

hp pro_x2_612_g1_firmware

hp probook_11_g1_firmware

hp probook_11_g2_firmware

hp probook_430_g1_firmware

hp probook_430_g2_firmware

hp probook_430_g3_firmware

hp probook_440_g1_firmware

hp probook_440_g2_firmware

hp probook_440_g3_firmware

hp probook_450_g1_firmware

hp probook_450_g2_firmware

hp probook_450_g3_firmware

hp probook_470_g1_firmware

hp probook_470_g2_firmware

hp probook_470_g3_firmware

hp probook_640_g1_firmware

hp probook_640_g2_firmware

hp probook_650_g1_firmware

hp probook_650_g2_firmware

hp probook_x360_11_g1_firmware

hp prodesk_400_g1_dm_firmware

hp prodesk_400_g2_dm_firmware

hp prodesk_400_g2.5_sff_firmware

hp prodesk_400_g3_sff_firmware

hp prodesk_405_g2_mt_firmware

hp prodesk_485_g2_mt_firmware

hp prodesk_480_g3_sff_firmware

hp prodesk_490_g2_mt_firmware

hp prodesk_490_g3_sff_firmware

hp prodesk_498_g2_mt_firmware

hp prodesk_498_g3_sff_firmware

hp prodesk_600_g2_dm_firmware

hp prodesk_600_g2_sff_firmware

hp proone_400_g2_aio_firmware

hp proone_600_g2_aio_firmware

hp rp2_retail_system_firmware

hp rp9_g1_retail_system_9015_firmware

hp rp9_g1_retail_system_9018_firmware

hp zbook_14_g2_firmware

hp zbook_14_firmware

hp zbook_15_g2_firmware

hp zbook_15_g3_firmware

hp zbook_15_firmware

hp zbook_15u_g2_firmware

hp zbook_15u_g3_firmware

hp zbook_17_g2_firmware

hp zbook_17_g3_firmware

hp zbook_17_firmware

hp zbook_studio_g3_firmware

hp z1_g3_firmware

hp z2_mini_g3_firmware

hp z238_microtower_firmware

hp z240_sff_firmware

hp z240_tower_firmware

hp sprout_pro_firmware

Vendor Advisories

A potential security vulnerability has been identified which involves possible execution of arbitrary code during boot services that can result in elevation of privilege The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code ...
A potential security vulnerability has been identified which involves possible execution of arbitrary code during boot services that can result in elevation of privilege The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code ...