CVE-2026-0438

A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM, potentially compromising the system’s confidentiality, integrity, and availability.
CVSS

No CVSS.

Configurations

No configuration.

History

15 May 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 02:16

Updated : 2026-05-15 14:10


NVD link : CVE-2026-0438

Mitre link : CVE-2026-0438

CVE.ORG link : CVE-2026-0438


JSON object : View

Products Affected

No product.

CWE
CWE-1072

Data Resource Access without Use of Connection Pooling