First published: Fri Mar 04 2016(Updated: )
Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP EliteBook 725 G3 Firmware | ||
HP EliteBook 745 G3 Firmware | ||
HP EliteBook 755 G3 Firmware | ||
HP 700 Series Firmware | =1.08 | |
HP EliteDesk 800 G2 Tower | ||
HP EliteDesk 800 SFF | ||
HP 800 series firmware | =2.09 | |
HP z240 Tower Workstation | ||
HP z240 Tower Workstation | ||
HP Z240 Tower Firmware | =1.11 | |
HP 700 Series Firmware | =2.09 | |
HP EliteDesk 705 G2 mt SFF | ||
HP z238 microtower workstation | ||
HP Z238 Firmware | =1.11 | |
HP ZBook 15u G3 | ||
HP ZBook 15u G3 Firmware | ||
HP ZBook 17 G3 Firmware | ||
HP ZBook Firmware | =1.03 | |
HP EliteDesk 800 35W G2 Desktop Mini PC | ||
HP mp9 g2 retail System firmware | ||
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
HP 800 series firmware | =2.1 | |
HP EliteBook 820 G3 Firmware | ||
HP EliteBook 840 G3 Firmware | ||
HP EliteBook 850 G3 | ||
HP 1000 series firmware | =1.04 | |
HP EliteBook Folio 1012 x2 G2 | ||
HP 1000 series firmware | =1.1 | |
HP EliteBook Folio 1040 G3 Firmware | ||
HP 1000 series firmware | =1.01 | |
HP EliteDesk 705 G2 DM | ||
HP 700 Series Firmware | =2.05 | |
HP mt42 Mobile Thin Client Firmware | ||
HP 700 Series Firmware | =1.05 | |
HP ZBook Studio G3 Firmware | ||
HP ZBook Firmware | =1.04 | |
Zyxel GS1900-10HP firmware | <2.50\(aazi.0\)c0 | |
HP 700 Series Firmware | =2.07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2243 has a severity rating that indicates it can lead to a denial of service through BIOS recovery failure.
To fix CVE-2016-2243, users should update to the latest firmware versions provided by HP.
CVE-2016-2243 affects specific HP Commercial PCs and laptops that use the vulnerable firmware versions.
Currently, disabling administrative access may prevent exploitation of CVE-2016-2243, but updating firmware is the recommended solution.
CVE-2016-2243 is classified as a local denial of service vulnerability affecting the BIOS.