SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Insyde
Insyde insydeh2o
Vendors & Products Insyde
Insyde insydeh2o

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Description SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
Title FMTSWriteUseIntelLib: FMTS SMM IHISI Buffer Overflow
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Insyde

Published: 2026-08-26T01:00:25.855Z

Updated: 2026-08-26T15:29:45.529Z

Reserved: 2026-05-28T06:24:59.358Z

Link: CVE-2026-9805

cve-icon Vulnrichment

Updated: 2026-08-26T15:29:37.172Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-26T05:18:28.547

Modified: 2026-08-31T19:27:23.020

Link: CVE-2026-9805

cve-icon Redhat

No data.