CVE-2026-9805: FMTSWriteUseIntelLib: FMTS SMM IHISI Buffer Overflow
Published Aug 26, 2026
·Updated
SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
Event History
Aug 26, 2026
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are required to exploit this issue?
The supplied severity vector indicates physical access, high attack complexity, high privileges, and required user interaction. The impact is limited to integrity and availability; no confidentiality impact is listed.
2
Which component and operation are affected?
The issue is in the SMM IHISI command handler FMTSWriteUseIntelLib when processing FMTS command 0x32. That handler reads and writes data without checking buffer size, which can result in a buffer overflow.