CVE-2021-39297
📋 TL;DR
This UEFI firmware vulnerability in certain HP PC products allows attackers with physical or administrative access to execute arbitrary code at the firmware level. This affects specific HP PC models with vulnerable BIOS versions, potentially compromising the entire system before the operating system loads.
💻 Affected Systems
- HP PC products (specific models listed in HP advisory)
📦 What is this software?
Elitebook 840 G5 Healthcare Edition Firmware by Hp
View all CVEs affecting Elitebook 840 G5 Healthcare Edition Firmware →
Elitebook 840 G6 Healthcare Edition Firmware by Hp
View all CVEs affecting Elitebook 840 G6 Healthcare Edition Firmware →
Elitedesk 800 35w G4 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 35w G4 Desktop Mini Pc Firmware →
Elitedesk 800 65w G4 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 65w G4 Desktop Mini Pc Firmware →
Elitedesk 800 95w G4 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 95w G4 Desktop Mini Pc Firmware →
Elitedesk 800 G4 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Small Form Factor Pc Firmware →
Elitedesk 800 G4 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Tower Pc Firmware →
Elitedesk 800 G4 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Tower Pc Firmware →
Elitedesk 800 G4 Workstation Edition Firmware by Hp
View all CVEs affecting Elitedesk 800 G4 Workstation Edition Firmware →
Elitedesk 800 G5 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Desktop Mini Pc Firmware →
Elitedesk 800 G5 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Small Form Factor Pc Firmware →
Elitedesk 800 G5 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G5 Tower Pc Firmware →
Elitedesk 800 G6 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Desktop Mini Pc Firmware →
Elitedesk 800 G6 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Small Form Factor Pc Firmware →
Elitedesk 800 G6 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G6 Tower Pc Firmware →
Elitedesk 800 G8 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Desktop Mini Pc Firmware →
Elitedesk 800 G8 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Small Form Factor Pc Firmware →
Elitedesk 800 G8 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 800 G8 Tower Pc Firmware →
Elitedesk 805 G6 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Desktop Mini Pc Firmware →
Elitedesk 805 G6 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Elitedesk 805 G6 Small Form Factor Pc Firmware →
Elitedesk 805 G8 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Desktop Mini Pc Firmware →
Elitedesk 805 G8 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Elitedesk 805 G8 Small Form Factor Pc Firmware →
Elitedesk 880 G4 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 880 G4 Tower Pc Firmware →
Elitedesk 880 G5 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 880 G5 Tower Pc Firmware →
Elitedesk 880 G6 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 880 G6 Tower Pc Firmware →
Elitedesk 880 G8 Tower Pc Firmware by Hp
View all CVEs affecting Elitedesk 880 G8 Tower Pc Firmware →
Eliteone 1000 G2 23.8 In All In One Business Pc Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In All In One Business Pc Firmware →
Eliteone 1000 G2 23.8 In Touch All In One Business Pc Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 23.8 In Touch All In One Business Pc Firmware →
Eliteone 1000 G2 27 In 4k Uhd All In One Business Pc Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 27 In 4k Uhd All In One Business Pc Firmware →
Eliteone 1000 G2 34 In Curved All In One Business Pc Firmware by Hp
View all CVEs affecting Eliteone 1000 G2 34 In Curved All In One Business Pc Firmware →
Eliteone 800 G4 23.8 In Healthcare Edition All In One Business Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 In Healthcare Edition All In One Business Pc Firmware →
Eliteone 800 G4 23.8 Inch Non Touch All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch All In One Pc Firmware →
Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Non Touch Gpu All In One Pc Firmware →
Eliteone 800 G4 23.8 Inch Touch All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch All In One Pc Firmware →
Eliteone 800 G4 23.8 Inch Touch Gpu All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G4 23.8 Inch Touch Gpu All In One Pc Firmware →
Eliteone 800 G5 23.8 In Healthcare Edition All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 In Healthcare Edition All In One Firmware →
Eliteone 800 G5 23.8 Inch All In One Firmware by Hp
View all CVEs affecting Eliteone 800 G5 23.8 Inch All In One Firmware →
Eliteone 800 G6 24 All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G6 24 All In One Pc Firmware →
Eliteone 800 G6 27 All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G6 27 All In One Pc Firmware →
Eliteone 800 G8 24 All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G8 24 All In One Pc Firmware →
Eliteone 800 G8 27 All In One Pc Firmware by Hp
View all CVEs affecting Eliteone 800 G8 27 All In One Pc Firmware →
Engage Flex Mini Retail System Firmware by Hp
View all CVEs affecting Engage Flex Mini Retail System Firmware →
Probook X360 11 G3 Education Edition Firmware by Hp
View all CVEs affecting Probook X360 11 G3 Education Edition Firmware →
Probook X360 11 G4 Education Edition Firmware by Hp
View all CVEs affecting Probook X360 11 G4 Education Edition Firmware →
Probook X360 11 G5 Education Edition Firmware by Hp
View all CVEs affecting Probook X360 11 G5 Education Edition Firmware →
Probook X360 11 G6 Education Edition Firmware by Hp
View all CVEs affecting Probook X360 11 G6 Education Edition Firmware →
Probook X360 11 G7 Education Edition Firmware by Hp
View all CVEs affecting Probook X360 11 G7 Education Edition Firmware →
Prodesk 400 G4 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G4 Desktop Mini Pc Firmware →
Prodesk 400 G5 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Desktop Mini Pc Firmware →
Prodesk 400 G5 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Microtower Pc Firmware →
Prodesk 400 G5 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G5 Small Form Factor Pc Firmware →
Prodesk 400 G6 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Desktop Mini Pc Firmware →
Prodesk 400 G6 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Microtower Pc Firmware →
Prodesk 400 G6 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G6 Small Form Factor Pc Firmware →
Prodesk 400 G7 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Microtower Pc Firmware →
Prodesk 400 G7 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 400 G7 Small Form Factor Pc Firmware →
Prodesk 405 G8 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Desktop Mini Pc Firmware →
Prodesk 405 G8 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 405 G8 Small Form Factor Pc Firmware →
Prodesk 480 G5 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 480 G5 Microtower Pc Firmware →
Prodesk 480 G6 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 480 G6 Microtower Pc Firmware →
Prodesk 480 G7 Pci Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 480 G7 Pci Microtower Pc Firmware →
Prodesk 600 G4 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Desktop Mini Pc Firmware →
Prodesk 600 G4 Microtower Pc \(with Pci Slot\) Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Microtower Pc \(with Pci Slot\) Firmware →
Prodesk 600 G4 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Microtower Pc Firmware →
Prodesk 600 G4 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G4 Small Form Factor Pc Firmware →
Prodesk 600 G5 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Desktop Mini Pc Firmware →
Prodesk 600 G5 Microtower Pc \(with Pci Slot\) Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Microtower Pc \(with Pci Slot\) Firmware →
Prodesk 600 G5 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Microtower Pc Firmware →
Prodesk 600 G5 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G5 Small Form Factor Pc Firmware →
Prodesk 600 G6 Desktop Mini Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Desktop Mini Pc Firmware →
Prodesk 600 G6 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Microtower Pc Firmware →
Prodesk 600 G6 Small Form Factor Pc Firmware by Hp
View all CVEs affecting Prodesk 600 G6 Small Form Factor Pc Firmware →
Prodesk 680 G4 Microtower Pc \(with Pci Slot\) Firmware by Hp
View all CVEs affecting Prodesk 680 G4 Microtower Pc \(with Pci Slot\) Firmware →
Prodesk 680 G4 Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 680 G4 Microtower Pc Firmware →
Prodesk 680 G6 Pci Microtower Pc Firmware by Hp
View all CVEs affecting Prodesk 680 G6 Pci Microtower Pc Firmware →
Proone 400 G4 20 Inch Non Touch All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 400 G4 20 Inch Non Touch All In One Business Pc Firmware →
Proone 400 G4 23.8 Inch Non Touch All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 400 G4 23.8 Inch Non Touch All In One Business Pc Firmware →
Proone 400 G5 20 Inch All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 400 G5 20 Inch All In One Business Pc Firmware →
Proone 400 G5 23.8 Inch All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 400 G5 23.8 Inch All In One Business Pc Firmware →
Proone 400 G6 20 All In One Pc Firmware by Hp
View all CVEs affecting Proone 400 G6 20 All In One Pc Firmware →
Proone 400 G6 24 All In One Pc Firmware by Hp
View all CVEs affecting Proone 400 G6 24 All In One Pc Firmware →
Proone 440 G4 23.8 Inch Non Touch All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 440 G4 23.8 Inch Non Touch All In One Business Pc Firmware →
Proone 440 G5 23.8 In All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 440 G5 23.8 In All In One Business Pc Firmware →
Proone 440 G6 24 All In One Pc Firmware by Hp
View all CVEs affecting Proone 440 G6 24 All In One Pc Firmware →
Proone 600 G4 21.5 Inch Touch All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 600 G4 21.5 Inch Touch All In One Business Pc Firmware →
Proone 600 G5 21.5 In All In One Business Pc Firmware by Hp
View all CVEs affecting Proone 600 G5 21.5 In All In One Business Pc Firmware →
Proone 600 G6 22 All In One Pc Firmware by Hp
View all CVEs affecting Proone 600 G6 22 All In One Pc Firmware →
Z1 Entry Tower G5 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G5 Workstation Firmware →
Z1 Entry Tower G6 Workstation Firmware by Hp
View all CVEs affecting Z1 Entry Tower G6 Workstation Firmware →
Z4 G4 Workstation \(core X\) Firmware by Hp
View all CVEs affecting Z4 G4 Workstation \(core X\) Firmware →
Z4 G4 Workstation \(core X\) Firmware by Hp
View all CVEs affecting Z4 G4 Workstation \(core X\) Firmware →
Z4 G4 Workstation \(core X\) Firmware by Hp
View all CVEs affecting Z4 G4 Workstation \(core X\) Firmware →
Z4 G4 Workstation \(xeon W\) Firmware by Hp
View all CVEs affecting Z4 G4 Workstation \(xeon W\) Firmware →
Z4 G4 Workstation \(xeon W\) Firmware by Hp
View all CVEs affecting Z4 G4 Workstation \(xeon W\) Firmware →
Z4 G4 Workstation \(xeon W\) Firmware by Hp
View all CVEs affecting Z4 G4 Workstation \(xeon W\) Firmware →
Zhan 66 Pro G3 22 All In One Pc Firmware by Hp
View all CVEs affecting Zhan 66 Pro G3 22 All In One Pc Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Complete system compromise with persistent firmware-level malware that survives OS reinstallation and disk replacement, enabling data theft, ransomware deployment, or system bricking.
Likely Case
Privilege escalation from administrative user to firmware-level control, allowing installation of persistent backdoors or disabling security features.
If Mitigated
Limited impact if physical access controls prevent unauthorized BIOS access and administrative privileges are tightly controlled.
🎯 Exploit Status
Requires administrative access or physical access to BIOS settings. No public exploit code available.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: BIOS updates specific to each affected HP PC model
Vendor Advisory: https://support.hp.com/us-en/document/ish_5661066-5661090-16
Restart Required: Yes
Instructions:
1. Identify exact HP PC model. 2. Visit HP support site. 3. Download latest BIOS update for your model. 4. Run BIOS update utility. 5. Restart system as prompted.
🔧 Temporary Workarounds
Restrict physical access
allPrevent unauthorized physical access to systems to block BIOS manipulation.
Enable BIOS password
allSet strong BIOS administrator password to prevent unauthorized BIOS changes.
🧯 If You Can't Patch
- Isolate affected systems on separate network segments
- Implement strict administrative access controls and monitoring
🔍 How to Verify
Check if Vulnerable:
Check HP advisory for affected models and compare with your system's model and BIOS version (check in BIOS setup or using 'wmic bios get smbiosbiosversion' on Windows).
Check Version:
Windows: wmic bios get smbiosbiosversion | Linux: sudo dmidecode -s bios-version
Verify Fix Applied:
Verify BIOS version after update matches patched version in HP advisory.
📡 Detection & Monitoring
Log Indicators:
- Unexpected BIOS update attempts
- BIOS configuration changes in system logs
- Failed BIOS password attempts
Network Indicators:
- Unusual outbound connections from systems with vulnerable BIOS
SIEM Query:
Search for BIOS-related events or unauthorized firmware update attempts in system logs.