HP released today BIOS updates to fix two high severity vulnerabilities that affect a wide range of computer and laptop products, which allow code execution with Kernel privileges.
See also: HP: Three serious vulnerabilities affect hundreds of printers

Kernel-level privileges are the highest privileges in Windows, allowing threat actors to execute any kernel-level, including manipulating drivers and accessing the BIOS.
See also: HP fixes 16 UEFI firmware bugs that allow hidden malware infections
The flaws are tracked as CVE-2021-3808 and CVE-2021-3809 and have a CVSS 3.1 score of 8.8, giving them a high severity rating. At this time, HP has not provided technical details about these flaws.

The list of affected products includes business notebooks such as Zbook Studio, ZHAN Pro, EliteBook, ProBook and Elite Dragonfly, professional desktops such as EliteDesk and ProDesk, retail PoS computers such as Engage, workstations such as Z1 and Z2, and thin client PCs.
For a complete list of all affected models and the corresponding SoftPaqs you should apply in each case, check the security advisory page and search for your device. Please note that not all products listed have received the patch.
The researcher reveals more
Nicholas Starke, the researcher who discovered these vulnerabilities in November 2021 and reported them to HP, explains the issue in more detail in a separate post.
The problem seems to be that an SMI handler can be activated from the operating system, for example, via the Windows kernel driver.

An attacker must locate the memory address of the “LocateProtocol” function and replace it with malicious code. Finally, the attacker can trigger code execution by instructing the SMI handler to execute it.
It is important to emphasize that in order to exploit the vulnerability, an attacker must have root/SYSTEM-level privileges on the target system and execute code in System Management Mode (SMM).
See also: Critical RCE flaws in PHP Everywhere plugin put WordPress sites at risk
The ultimate goal of such an attack would be to replace the machine's UEFI Implementation (BIOS) with BIOS images controlled by the attackers. This means that an attacker could install persistent malware that cannot be removed by antivirus tools, not even by operating system reinstallations.
Finally, it is also important to highlight that some HP computer models have mitigations that the attacker would have to bypass for the exploit to work , such as the HP Sure Start system.
The researcher explains that HP Sure Start can detect such violations and shut down the host after the memory corruption. Then, on first boot, a warning will appear to the user along with a prompt to approve the system boot.
HP's latest fixes come just two months after the computer maker patched 16 UEFI firmware bugs and three months after addressing a different set of BIOS flaws
Therefore, if you have not yet applied the security updates, make sure to back up your data on a separate system and do it now.
Information source: bleepingcomputer.com
