Saturday, June 14, 2025
Homecyber securityNew 16 High-Severity UEFI Firmware Bugs Uncovered in Millions of HP Devices

New 16 High-Severity UEFI Firmware Bugs Uncovered in Millions of HP Devices

Published on

SIEM as a Service

Follow Us on Google News

The cybersecurity analysts at HP have recently revealed 16 high-severity UEFI firmware bugs in millions of HP devices. And by exploiting these vulnerabilities a threat actor can gain high privileges on the affected devices, and not only that even also allow the attacker to evade AV tools and remain undetectable.

All these bugs have affected multiple HP models from different segments like:-

  • HP laptops
  • HP desktop computers
  • HP PoS systems
  • HP edge computing nodes

While these 16 high-severity UEFI firmware bugs were discovered by the security experts at Binarly security firm.

- Advertisement - Google News

Here’s what the Founder and CEO of Binarly, Alex Matrosov stated:-

“Binarly believes that the lack of a knowledge base of common firmware exploitation techniques and primitives related to UEFI firmware makes these failures repeatable for the entire industry. We are working hard to fill this gap by providing comprehensive technical details in our advisories. This knowledge base is crucial for developing effective mitigations and defense technologies for device security”

Vulnerabilities

After the discovery of these severe vulnerabilities, Binarly is collaborated with several security teams including HP’s and CERT/CC’s to understand the impact and scope for each of the vulnerabilities to mitigate them and protect the enterprise infrastructures globally.

Here we have listed all the 16 high-severity UEFI firmware bugs below:-

  1. CVE-2021-39297: It’s a DXE stack buffer overflow (arbitrary code execution) flaw with a CVSS score of 7.7.
  2. CVE-2021-39298: It’s an SMM callout (privilege escalation) flaw with a CVSS score of 8.8.
  3. CVE-2021-39299: It’s a DXE stack buffer overflow (arbitrary code execution) flaw with a CVSS score of 8.2.
  4. CVE-2021-39300: It’s a DXE stack overflow vulnerability (arbitrary code execution) flaw with a CVSS score of 8.2.
  5. CVE-2021-39301: It’s a DXE stack overflow (arbitrary code execution) flaw with a CVSS score of 7.7.
  6. CVE-2022-23924: It’s an SMM heap buffer overflow (arbitrary code execution) flaw with a CVSS score of 8.2.
  7. CVE-2022-23925: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  8. CVE-2022-23926: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  9. CVE-2022-23927: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  10. CVE-2022-23928: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  11. CVE-2022-23929: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  12. CVE-2022-23930: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  13. CVE-2022-23931: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.
  14. CVE-2022-23932: It’s an SMM callout (privilege escalation) flaw with a CVSS score of 8.2.
  15. CVE-2022-23933: It’s an SMM callout (privilege escalation) flaw with a CVSS score of 8.2.
  16. CVE-2022-23934: It’s an SMM memory corruption (arbitrary code execution) flaw with a CVSS score of 8.2.

Exploitation

By exploiting these above-mentioned security flaws, an attacker can perform:- 

  • Privileged code execution in the firmware of affected devices.
  • Code execution below the operating system.
  • Deliver persistent malicious code that endures OS re-installations.
  • Bypass of endpoint security solutions (EDR/AV).
  • Bypass of Secure Boot.
  • Bypass of Virtualization-Based Security isolation.

Apart from this, the consequences of third-party risks from known vulnerabilities are commonly undervalued by several device manufacturers and firmware development companies.

But, the current discovery and data depict that the scenario is completely different from the assumed one. As there are many vendors who have not yet patched several know vulnerabilities.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Kali Linux 2025.2 Released: New Tools, Smartwatch and Car Hacking Added

Kali Linux, the preferred distribution for security professionals, has launched its second major release...

Arsen Launches AI-Powered Vishing Simulation to Help Organizations Combat Voice Phishing at Scale

Arsen, the cybersecurity startup known for defending organizations against social engineering threats, has announced...

NIST Releases New Guide – 19 Strategies for Building Zero Trust Architectures

The National Institute of Standards and Technology (NIST) has released groundbreaking guidance to help...

Spring Framework Flaw Enables Remote File Disclosure via “Content‑Disposition” Header

A medium-severity reflected file download (RFD) vulnerability (CVE-2025-41234) in VMware's Spring Framework has been...

Credential Abuse: 15-Min Attack Simulation

Credential Abuse Unmasked

Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our live, 15-min attack simulation with Karthik Krishnamoorthy (CTO - Indusface) and Phani Deepak Akella (VP of Marketing - Indusface) to see hackers move from first probe to full account takeover.

Discussion points


Username & email enumeration – how a stray status-code reveals valid accounts.
Password spraying – low-and-slow guesses that evade basic lockouts.
Credential stuffing – lightning-fast reuse of breach combos at scale.
MFA / session-token bypass – sliding past second factors with stolen cookies.

More like this

Kali Linux 2025.2 Released: New Tools, Smartwatch and Car Hacking Added

Kali Linux, the preferred distribution for security professionals, has launched its second major release...

NIST Releases New Guide – 19 Strategies for Building Zero Trust Architectures

The National Institute of Standards and Technology (NIST) has released groundbreaking guidance to help...

Spring Framework Flaw Enables Remote File Disclosure via “Content‑Disposition” Header

A medium-severity reflected file download (RFD) vulnerability (CVE-2025-41234) in VMware's Spring Framework has been...