CVE-2019-12532: Insyde h2oelv

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.

Affected products

  • Insyde h2oelv: before 100.00.02.08 (fixed in 100.00.02.08)
  • Insyde h2offt: from 3.02, up to and including 5.28; from 100.00.00.00, up to and including 100.00.08.23; from 200.00.00.01, up to and including 200.00.00.05
  • Insyde h2ooae: before 200.00.00.02 (fixed in 200.00.00.02)
  • Insyde h2opcm: before 100.00.06.00 (fixed in 100.00.06.00)
  • Insyde h2osde: before 200.00.00.07 (fixed in 200.00.00.07)
  • Insyde h2ouve: before 200.00.02.02 (fixed in 200.00.02.02)

Published 2019-08-26. Last modified 2026-06-17.