Lucene search

K
hpHP Product Security Response TeamHPSBHF03864
HistorySep 21, 2023 - 12:00 a.m.

AMD Client UEFI DXE Driver Memory Leaks September 2023 Security Update

2023-09-2100:00:00
HP Product Security Response Team
support.hp.com
4
amd
uefi
dxe driver
memory leaks
security update
hp
firmware
denial of service
information disclosure
vulnerabilities
softpaqs
affected platforms

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

AMD has informed HP of potential vulnerabilities identified in some AMD client platform firmware components, which might allow denial of service or information disclosure. AMD is releasing firmware updates to mitigate these vulnerabilities.

AMD has released updates to mitigate the potential vulnerabilities. HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the potential vulnerabilities. See the affected platforms listed below.

Affected configurations

Vulners
Node
hpelitebook_645_14_inch_g9_notebook_pc_firmwareRange<01.12.01
OR
hpelitebook_655_15.6_inch_g9_notebook_pc_firmwareRange<01.12.01
OR
hpelitebook_835_13_inch_g9_notebook_pc_firmwareRange<01.06.00
OR
hphp_elitebook_835_g8Range<01.14.00
OR
hpelitebook_845_14_inch_g9_notebook_pc_firmwareRange<01.06.00
OR
hphp_elitebook_845_g8Range<01.14.00
OR
hphp_elitebook_855_g7Range<01.14.00
OR
hphp_elitebook_855_g8Range<01.14.00
OR
hpelitebook_865_16_inch_g9_notebook_pc_firmwareRange<01.06.00
OR
hpelitebook_830_13.3_inch_g9_notebook_pc_firmwareRange<01.12.00
OR
hpprobook_445_14_inch_g9_notebook_pc_firmwareRange<01.12.00
OR
hphp_probook_445_g7Range<01.14.00
OR
hphp_probook_445_g8Range<01.14.00
OR
hpprobook_455_15.6_inch_g9_notebook_pc_firmwareRange<01.12.00
OR
hphp_probook_455_g7Range<01.14.00
OR
hphp_probook_455_g8Range<01.14.00
OR
hphp_probook_635_aero_g7Range<01.14.00
OR
hphp_probook_635_aero_g8Range<01.14.00
OR
hphp_probook_x360_435_g7Range<01.14.00
OR
hpprobook_x360_435_g8_notebook_pc_firmwareRange<01.14.21
OR
hpzhan_66_pro_a_14_g3_firmwareRange<01.14.00
OR
hpzhan_66_pro_a_14_g4_notebook_pc_firmwareRange<01.14.00
OR
hpzhan_66_pro_a_14_g5_notebook_pc_firmwareRange<01.12.01
OR
hphp_elitedesk_705_g5_desktop_mini_pcRange<02.18.00
OR
hphp_elitedesk_705_g5_small_form_factor_pcRange<02.18.00
OR
hphp_elitedesk_805_g6_desktop_mini_pcRange<02.13.00
OR
hphp_elitedesk_805_g6_small_form_factor_pcRange<02.13.00
OR
hphp_elitedesk_805_g8_desktop_mini_pcRange<02.09.00
OR
hphp_elitedesk_805_g8_small_form_factor_pcRange<02.09.00
OR
hphp_prodesk_405_g6_small_form_factor_pcRange<02.13.00
OR
hphp_prodesk_405_g8_small_form_factor_pcRange<02.09.00
OR
hpmt32_mobile_thin_client_firmwareRange<01.11.00
OR
hpmt46_mobile_thin_client_firmwareRange<01.11.00
OR
hpelite_mt645_g7_firmwareRange<01.11.00
OR
hphp_14-em0xxxRange<F.06
OR
hphp_14-fq0xxxRange<F.67
OR
hphp_14-fq1xxx\,_14z-fq100Range<F.27
OR
hphp_14-fq2xxx\,_14z-fq200Range<F.12
OR
hphp_14-hr0xxxRange<F.06
OR
hphp_14s-fq0xxxRange<F.67
OR
hphp_14s-fq1xxxRange<F.27
OR
hphp_14s-fq2xxxRange<F.12
OR
hphp_14s-fr0xxxRange<F.67
OR
hphp_14s-fr1xxxRange<F.27
OR
hphp_14s-fr2xxxRange<F.12
OR
hphp_14s-fy0xxxRange<F.67
OR
hphp_14s-fy1xxxRange<F.27
OR
hphp_14s-fy2xxxRange<F.12
OR
hphp_15-e3xxx\,_15z-e300Range<F.12
OR
hphp_15-ef0xxx\,_15z-ef000Range<F.67
OR
hphp_15-ef1xxx\,_15z-ef100Range<F.67
OR
hphp_15-ef2xxx\,_15z-ef200Range<F.27
OR
hphp_15-fc0xxxRange<F.09
OR
hphp_15-kr0xxxRange<F.09
OR
hphp_15s-eq0xxxRange<F.67
OR
hphp_15s-eq1xxxRange<F.67
OR
hphp_15s-eq2xxxRange<F.27
OR
hphp_15s-eq3xxxRange<F.12
OR
hphp_15s-er0xxxRange<F.67
OR
hphp_15s-er1xxxRange<F.67
OR
hphp_15s-er2xxxRange<F.27
OR
hphp_15s-er3xxxRange<F.12
OR
hphp_15s-ey0xxxRange<F.67
OR
hphp_15s-ey1xxxRange<F.67
OR
hphp_15s-ey2xxxRange<F.27
OR
hphp_15s-ey3xxxRange<F.12
OR
hphp_17-ca3xxx\,_17z-ca300Range<F.63
OR
hphp_17-cp1xxx\,_17z-cp100Range<F.11
OR
hphp_17-cp2xxxRange<F.13
OR
hphp_17-cp3xxxRange<F.03
OR
hphp_envy_x360_13-ay0xxx\,_13z-ay000Range<F.22
OR
hphp_envy_x360_13-ay1xxx\,_13z-ay100Range<F.06
OR
hphp_envy_x360_13m-ay0xxxRange<F.22
OR
hphp_envy_x360_15-ds1xxx\,_15z-ds100Range<F.11
OR
hphp_envy_x360_15-ee0xxx\,_15z-ee000Range<F.22
OR
hphp_envy_x360_15-eu0xxx\,_15z-eu000Range<F.11
OR
hphp_envy_x360_15-eu1xxxRange<F.06
OR
hphp_envy_x360_15-ey0xxxRange<F.14
OR
hphp_envy_x360_15-ey1xxxRange<F.04
OR
hphp_envy_x360_15-fh0xxxRange<F.05
OR
hphp_envy_x360_15m-ee0xxxRange<F.22
OR
hphp_envy_x360_15m-eu0xxxRange<F.11
OR
hphp_pavilion_14-ec0xxx\,_14z-ec000Range<F.12
OR
hphp_pavilion_14-ec1xxx\,_14z-ec100Range<F.05
OR
hphp_pavilion_15-eh0xxx\,_15z-eh000Range<F.24
OR
hphp_pavilion_15-eh1xxxRange<F.23
OR
hphp_pavilion_15-eh2xxx\,_15z-eh200Range<F.07
OR
hphp_pavilion_15-eh3xxxRange<F.03
OR
hphp_pavilion_aero_13-be0xxx\,_13z-be000Range<F.11
OR
hphp_pavilion_aero_13-be1xxx\,_13z-be100Range<F.09
OR
hphp_pavilion_aero_13-be2xxxRange<F.12
OR
hphp_pavilion_14-ec0xxxRange<F.16
OR
hphp_pavilion_14-ec1xxx\,_14z-ec100Range<F.29
OR
hphp_pavilion_15-cw0xxx\,_15z-cw100Range<F.23
OR
hphp_15-gw0xxx\,_15z-gw000Range<F.21
OR
hpvictus_by_hp_15-fb1xxxRange<F.23
OR
hpvictus_by_hp_16-e0xxxRange<F.19
OR
hpomen_gaming_hubRange<F.16
OR
hpomen_gaming_hubRange<F.17
OR
hpvictus_by_hp_16-e0xxxRange<F.18
OR
hpvictus_by_hp_16-e1xxx\,_16z-e100Range<F.19
OR
hphp_245_g10Range<F.07
OR
hp245_g9_firmwareRange<F.11
OR
hphp_247_g8_pcRange<F.70
OR
hphp_247_g8_pcRange<F.26
OR
hphp_255_g10Range<F.09
OR
hphp_255_g8_pcRange<F.33
OR
hphp_255_g1_notebook_pc_firmwareRange<F.12
OR
hphp_zhan_99_g4_mobile_workstationRange<F.09
OR
hphp_zhan_99_mobile_workstation_g2Range<F.23
OR
hphp_all-in-one_24-cb0xxxRange<F.12
OR
hphp_all-in-one_24-cb1xxxRange<F.11
OR
hphp_all-in-one_24-ck0xxxRange<F.11
OR
hphp_all-in-one_24-cr0xxxRange<F.05
OR
hphp_all-in-one_24-dp0xxxRange<F.42
OR
hphp_all-in-one_27-cb0xxxRange<F.12
OR
hphp_all-in-one_27-cb1xxxRange<F.11
OR
hphp_all-in-one_27-cr0xxxRange<F.05
OR
hphp_all-in-one_27-dp0xxxRange<F.42
OR
hphp_envy_te01-0xxxRange<F.44
OR
hphp_envy_te01-1xxxRange<F.33
OR
hphp_m01-d0xxxRange<F.44
OR
hphp_m01-d1xxxRange<F.33
OR
hphp_m01-f0xxxRange<F.44
OR
hphp_m01-f1xxxRange<F.33
OR
hphp_m01-f3xxxRange<F.12
OR
hphp_n01-f2xxxRange<F.12
OR
hphp_pavilion_all-in-one_24-ca0xxxRange<F.12
OR
hphp_pavilion_all-in-one_24-ca1xxxRange<F.11
OR
hphp_pavilion_all-in-one_24-k0xxxRange<F.13
OR
hphp_pavilion_all-in-one_24-qc0xxxRange<F.13
OR
hphp_pavilion_all-in-one_27-ca0xxxRange<F.12
OR
hphp_pavilion_all-in-one_27-ca1xxxRange<F.11
OR
hphp_pavilion_all-in-one_27-d0xxxRange<F.13
OR
hphp_pavilion_all-in-one_27-qc0xxxRange<F.13
OR
hphp_pavilion_tp01-0xxxRange<F.44
OR
hphp_pavilion_tp01-1xxxRange<F.33
OR
hphp_pavilion_tp01-2xxxRange<F.21
OR
hphp_pavilion_tp01-0xxxRange<F.44
OR
hphp_pavilion_tp01-1xxxRange<F.33
OR
hphp_pavilion_tp01-2xxxRange<F.21
OR
hphp_desktop_390-0xxxRange<F.25
OR
hphp_envy_desktop_te02-1xxxRange<F.17
OR
hphp_envy_desktop_te02-1xxxRange<F.17
OR
hphp_desktop_390-0xxxRange<F.25
OR
hphp_envy_desktop_te02-1xxxRange<F.17
OR
hpvictus_by_hp_15l_tg02-0xxxRange<F.12
OR
hpvictus_by_hp_15l_tg02-0xxxRange<F.12
OR
hpvictus_by_hp_15l_tg02-0xxxRange<F.14
OR
hpvictus_by_hp_15l_tg02-0xxxRange<F.14
OR
hpomen_gaming_hubRange<F.14
OR
hpomen_gaming_hubRange<F.25
OR
hpvictus_by_hp_15l_tg02-0xxxRange<F.11
OR
hphp_205_g8_24_all-in-one_pcRange<F.12
OR
hphp_205_g8_24_all-in-one_pcRange<F.15
OR
hphp_205_pro_g8_24_all-in-one_pcRange<F.12
OR
hphp_205_pro_g8_24_all-in-one_pcRange<F.15
OR
hphp_285_g6_microtower_pcRange<F.24
OR
hphp_285_g8_microtower_pcRange<F.22
OR
hphp_285_pro_g6_microtower_pcRange<F.24
OR
hphp_285_pro_g8_microtower_pcRange<F.22
OR
hphp_295_g8_microtower_pcRange<F.22
OR
hpzhan_66_pro_g3_24_all-in-one_pc_firmwareRange<F.12
OR
hpzhan_66_pro_g3_24_all-in-one_pc_firmwareRange<F.15
OR
hphp_zhan_99_pro_g2_microtower_pcRange<F.24

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for HPSBHF03864