First published: Tue Nov 05 2019(Updated: )
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP 260 G1 Desktop Mini | <2.27 | |
HP 260 G1 DM Firmware | ||
HP 280 Pro G1 Firmware | <80.3 | |
HP 280 Pro G1 | ||
HP 285 G2 Firmware | <a0.23 | |
HP 285 G2 Firmware | ||
HP 340 G3 Firmware | <f.48 | |
HP 340 G3 Firmware | ||
HP 340 G4 Firmware | <f.55 | |
HP 340 G4 Firmware | ||
HP 346 G3 | <f.48 | |
HP 346 G3 Firmware | ||
HP 346 G4 Firmware | <f.46 | |
HP 346 G4 | ||
HP 348 G3 Firmware | <f.48 | |
HP 348 G3 Firmware | ||
HP 348 g4 firmware | <f.55 | |
HP 348 G4 | ||
HP Elite Slice Firmware | <2.42 | |
HP Elite Slice Firmware | ||
HP Elite x2 1011 G1 Firmware | <1.27 | |
HP Elite x2 1011 G1 Firmware | ||
HP Elite x2 1012 G1 Tablet Firmware | <1.42 | |
HP Elite x2 1012 G1 Tablet with Travel Keyboard Firmware | ||
HP EliteBook 1030 G1 Firmware | <1.42 | |
HP EliteBook 1030 G1 Firmware | ||
HP EliteBook 1040 G2 Firmware | <1.17 | |
HP EliteBook 1040 G2 Firmware | ||
HP EliteBook 720 G1 Firmware | <1.48 | |
HP EliteBook 720 G1 Firmware | ||
HP EliteBook 720 G2 Firmware | <1.29 | |
HP EliteBook 720 G2 Firmware | ||
HP EliteBook 740 G1 Firmware | <1.48 | |
HP EliteBook 740 G1 Firmware | ||
HP EliteBook 740 G2 | <1.29 | |
HP EliteBook 740 G2 Firmware | ||
HP EliteBook 750 G1 Firmware | <1.48 | |
HP EliteBook 750 G1 Firmware | ||
HP EliteBook 750 G2 Firmware | <1.29 | |
HP EliteBook 750 G2 Firmware | ||
HP EliteBook 820 G1 Firmware | <1.48 | |
HP EliteBook 820 G1 Firmware | ||
HP EliteBook 820 G2 Firmware | <1.29 | |
HP EliteBook 820 G2 Firmware | ||
HP EliteBook 820 G3 Firmware | <1.42 | |
HP EliteBook 820 G3 Firmware | ||
HP EliteBook 828 G3 Firmware | <1.42 | |
HP EliteBook 828 G3 Firmware | ||
HP EliteBook 840 G1 Firmware | <1.48 | |
HP EliteBook 840 G1 Firmware | ||
HP EliteBook 840 G2 Firmware | <1.29 | |
HP EliteBook 840 G2 Firmware | ||
HP EliteBook 840 G3 Firmware | <1.42 | |
HP EliteBook 840 G3 Firmware | ||
HP EliteBook 848 G3 Firmware | <1.42 | |
HP EliteBook 848 G3 Firmware | ||
HP EliteBook 850 G1 Firmware | <1.48 | |
HP EliteBook 850 G1 Firmware | ||
HP EliteBook 850 G2 Firmware | <1.29 | |
HP EliteBook 850 G2 Firmware | ||
HP EliteBook 850 G3 Firmware | <1.42 | |
HP EliteBook 850 G3 | ||
HP EliteBook Folio 1020 G1 Firmware | <1.24 | |
HP EliteBook Folio 1020 G1 Firmware | ||
HP EliteBook Folio 1020 G1 Firmware | <1.24 | |
HP EliteBook Folio 1020 G1 Firmware | ||
HP EliteBook Folio 1040 G1 | <1.44 | |
HP EliteBook Folio 1040 G1 Firmware | ||
HP EliteBook Folio 1040 G3 Firmware | <1.42 | |
HP EliteBook Folio 1040 G3 Firmware | ||
HP EliteBook Folio 9480m Firmware | <1.49 | |
HP EliteBook Folio 9480m Firmware | ||
HP EliteBook Folio G1 Firmware | <1.42 | |
HP EliteBook Folio G1 Firmware | ||
HP EliteBook Revolve 810 G2 Firmware | <1.45 | |
HP EliteBook Revolve 810 G2 Firmware | ||
HP EliteBook Revolve 810 G3 Firmware | <1.2 | |
HP EliteBook Revolve 810 G3 Firmware | ||
HP EliteDesk 800 65w G2 Desktop Mini Firmware | <2.42 | |
HP EliteDesk 800 35W G2 Desktop Mini PC | ||
HP EliteDesk 800 G2 Small Form Factor PC Firmware | <2.42 | |
HP EliteDesk 800 G2 Small Form Factor PC Firmware | ||
HP EliteDesk 800 G2 Tower PC Firmware | <2.42 | |
HP EliteDesk 800 G2 Tower | ||
HP EliteOne 800 G2 AIO Firmware | <2.42 | |
HP EliteOne 800 G2 AIO Firmware | ||
HP ElitePad 1000 G2 Firmware | <1.48 | |
HP ElitePad 1000 G2 Firmware | ||
HP mp9 g2 retail System firmware | <2.42 | |
HP mp9 g2 retail System firmware | ||
HP Pro Tablet 10 EE G1 | <1.31 | |
HP Pro Tablet 10 EE G1 Firmware | ||
HP Pro Tablet 608 G1 Firmware | <1.21 | |
HP Pro Tablet 608 G1 Firmware | ||
HP Pro Tablet 610 G1 | <f.16 | |
HP Pro Tablet 610 G1 Firmware | ||
HP Pro x2 612 G1 Firmware | <1.48 | |
HP Pro x2 612 G1 Firmware | ||
HP ProBook 11 G1 Firmware | <1.17 | |
HP ProBook 11 G1 Firmware | ||
HP ProBook 11 G2 Firmware | <1.42 | |
HP ProBook 11 G2 Firmware | ||
HP ProBook 430 G1 Firmware | <1.49 | |
HP ProBook 430 G1 | ||
HP ProBook 430 G2 Firmware | <1.52 | |
HP ProBook 430 G2 Firmware | ||
HP ProBook 430 G3 Firmware | <1.42 | |
HP ProBook 430 G3 Firmware | ||
HP ProBook x360 440 G1 Firmware | <1.49 | |
HP ProBook 440 G1 Firmware | ||
HP ProBook 440 G2 Firmware | <1.52 | |
HP ProBook 440 G2 Firmware | ||
HP ProBook 440 G3 Firmware | <1.42 | |
HP ProBook 440 G3 Firmware | ||
HP ProBook 450 G1 Firmware | <1.49 | |
HP ProBook 450 G1 | ||
HP ProBook 450 G2 Firmware | <1.52 | |
HP ProBook 450 G2 Firmware | ||
HP ProBook 450 G3 Firmware | <1.42 | |
HP ProBook 450 G3 Firmware | ||
HP ProBook 470 G1 Firmware | <1.49 | |
HP ProBook 470 G1 Firmware | ||
HP ProBook 470 G2 Firmware | <1.52 | |
HP ProBook 470 G2 Firmware | ||
HP ProBook 470 G3 Firmware | <1.42 | |
HP ProBook 470 G3 Firmware | ||
HP ProBook 640 G1 Firmware | <1.49 | |
HP ProBook 640 G1 Firmware | ||
HP ProBook 640 G2 Firmware | <1.42 | |
HP ProBook 640 G2 Firmware | ||
HP ProBook 650 G1 Firmware | <1.49 | |
HP ProBook 650 G1 Firmware | ||
HP ProBook 650 G2 Firmware | <1.42 | |
HP ProBook 650 G2 Firmware | ||
HP ProBook x360 11 G1 Firmware | <1.3 | |
HP ProBook x360 11 G1 Firmware | ||
HP ProDesk 400 G1 DM Firmware | <2.27 | |
HP ProDesk 400 G1 DM | ||
HP ProDesk 400 G2 DM Firmware | <2.42 | |
HP ProDesk 400 G2 DM Firmware | ||
HP ProDesk 400 G2.5 SFF Firmware | <2.26 | |
HP ProDesk 400 G2.5 SFF Firmware | ||
HP ProDesk 400 G3 SFF Firmware | <2.42 | |
HP ProDesk 400 G3 SFF Firmware | ||
HP ProDesk 405 G2 MT | <2.29 | |
HP ProDesk 405 G2 MT Firmware | ||
HP ProDesk 485 G2 MT | <2.29 | |
HP ProDesk 485 G2 MT Firmware | ||
HP ProDesk 480 G3 SFF Firmware | <2.42 | |
HP ProDesk 480 G3 SFF Firmware | ||
HP ProDesk 490 G2 MT | <2.31 | |
HP ProDesk 490 G2 MT Firmware | ||
HP ProDesk 490 G3 SFF | <2.42 | |
HP ProDesk 490 G3 SFF Firmware | ||
HP ProDesk 498 G2 MT | <2.31 | |
HP ProDesk 498 G2 MT | ||
HP ProDesk 498 G3 SFF | <2.42 | |
HP ProDesk 498 G3 SFF Firmware | ||
HP ProDesk 600 G2 Desktop Mini Firmware | <2.42 | |
HP ProDesk 600 G2 DM Firmware | ||
HP ProDesk 600 G2 Small Form Factor PC Firmware | <2.42 | |
HP ProDesk 600 G2 SFF Firmware | ||
HP ProOne 400 G2 AIO | <2.42 | |
HP ProOne 400 G2 | ||
HP ProOne 600 G2 AIO Firmware | <2.42 | |
HP ProOne 600 G2 AIO Firmware | ||
HP rp2 retail system 2020 Firmware | <2.21 | |
HP rp2 retail system 2020 Firmware | ||
HP rp9 G1 Retail System Firmware | <2.42 | |
HP rp9 g1 retail System 9015 firmware | ||
HP rp9 G1 Retail System Firmware | <2.42 | |
HP rp9 g1 retail System 9018 firmware | ||
HP ZBook 14 G2 | <1.29 | |
HP ZBook 14 G2 Firmware | ||
HP ZBook 14 Firmware | <1.48 | |
HP ZBook 14 | ||
HP ZBook 15 G2 Firmware | <1.25 | |
HP ZBook 15u G2 | ||
HP ZBook 15 G3 Firmware | <1.42 | |
HP ZBook 15u G3 | ||
HP ZBook 15 Firmware | <1.46 | |
HP ZBook 15 Firmware | ||
HP ZBook 15u G2 Firmware | <1.29 | |
HP ZBook 15u G2 Firmware | ||
HP ZBook 15u G3 | <1.42 | |
HP ZBook 15u G3 Firmware | ||
HP ZBook 17 G2 Firmware | <1.25 | |
HP ZBook 17 G2 Firmware | ||
HP ZBook 17 G3 Firmware | <1.42 | |
HP ZBook 17 G3 Firmware | ||
HP ZBook 17 Firmware | <1.46 | |
HP ZBook 17 | ||
HP ZBook Studio G3 Firmware | <1.42 | |
HP ZBook Studio G3 | ||
HP Z1 G3 Firmware | <1.26 | |
HP Z1 All-in-One G3 | ||
HP Z2 Mini G3 Firmware | <1.77 | |
HP Z2 Mini G3 | ||
HP z238 Microtower Firmware | <1.77 | |
HP z238 microtower workstation | ||
HP Z240 Small Form Factor Firmware | <1.77 | |
HP Z240 SFF Workstation | ||
HP Z240 Tower Firmware | <1.77 | |
HP z240 Tower Workstation | ||
HP Sprout Pro by G2 Firmware | <a0.14 | |
HP Sprout Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16284 is rated as critical due to the potential for arbitrary code execution and privilege escalation.
To fix CVE-2019-16284, you should update the firmware of the affected HP products to the latest version provided by HP.
CVE-2019-16284 affects multiple HP products including HP 260 G1 DM, HP 280 Pro G1, HP 285 G2, and others listed in the vulnerability documentation.
CVE-2019-16284 typically requires physical access to the device, so remote exploitation is unlikely.
Currently, the recommended action is to apply firmware updates as there are no known effective workarounds for CVE-2019-16284.