• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
A_Gayathri
HP Administrator
Views : 37
No ratings

HP has identified potential security vulnerabilities in the Insyde UEFI firmware update utility used by certain HP PC products.

These vulnerabilities may allow an attacker with local access to perform:

  • Escalation of privilege
  • Denial of service
  • Information disclosure

HP has released SoftPaq updates to help mitigate these potential vulnerabilities.

HP Security Bulletin: HPSBHF03759 Rev. 1
Severity: High
Release date: December 13, 2021
Last updated: December 13, 2021
Category: PC

 

Security Vulnerabilities

The HP Security Bulletin identifies the following CVEs:

CVE CVSS 3.0 Score Potential Impact
CVE-2019-12532 7.8 Escalation of privilege
CVE-2021-33834 4.9 Potential security impact

CVE-2019-12532 is associated with the Insyde security advisory INSYDE-SA-2019001. The vendor ID for CVE-2021-33834 was listed as pending in the bulletin.

 

Resolution

HP has released firmware updates to address the potential vulnerabilities in the insyde f29 firmware update utilities used by affected HP products.

To resolve the issue:

  • Identify the HP PC model.
  • Check the list of affected products in the HP Security Bulletin.
  • Locate the corresponding BIOS package and minimum BIOS version for the product.
  • Download and install the applicable HP SoftPaq listed for the product.
  • If the listed SoftPaq is no longer available, check the HP Software and Driver Downloads page for the latest BIOS update available for the product.
  • Keep the system firmware and software up to date.

HP notes that newer SoftPaq versions may be released and that the minimum versions listed in the bulletin may become obsolete.

 

Affected Products

The bulletin provides affected products across multiple HP PC categories, including:

  • Business notebook PCs
  • Home notebook PCs
  • HP ENVY notebook PCs
  • HP Pavilion notebook PCs
  • HP Pavilion Gaming PCs
  • HP Pavilion x360 PCs
  • HP Stream PCs
  • HP ZBook mobile workstations
  • Other affected HP computer platforms listed in the bulletin

 

For each affected product, the bulletin provides:

  • Product name
  • Component type
  • Minimum required version
  • Last update
  • SoftPaq number
  • SoftPaq download information

Use the product-specific information in the HP bulletin to determine the applicable BIOS package.

 

Important Information

If a SoftPaq link listed in the bulletin is no longer available, HP recommends visiting HP Customer Support – Software and Driver Downloads and obtaining the latest update applicable to the product.

HP recommends keeping system firmware and software up to date.

Additional Information

Third-party security patches installed on systems running HP software products should be applied according to the customer's patch management policy.

For assistance implementing the recommendations in this Security Bulletin, use HP Support options.

To report a potential security vulnerability affecting an HP-supported product, contact HP Security at:

[email protected]

Revision History

Version Description Date
1 Initial Release December 13, 2021

Applicable HP Reference

HP Security Bulletin: HPSBHF03759 Rev. 1
Title: Insyde Firmware Utility December 2021 Security Updates

 

source: Insyde Firmware Utility December 2021 Security Updates

 

Need help or have any questions? Start a new discussion here and get the answers you need.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->