Your HP computer could have very serious security flaws — update now

HP Pavilion Aero 13 logo
(Image credit: Tom's Guide)

If you've got an HP desktop, laptop or tablet, you should check to see whether there's a BIOS/UEFI system-firmware update ready for it. Sixteen newly disclosed security flaws could let hackers implant deeply buried, undetectable malware, the company announced in a security bulletin yesterday (March 8).

Security firm Binarly, which discovered these 16 flaws, explained in a blog post yesterday that firmware-integrity checks, antivirus software or the Secure Boot process wouldn't be able to detect malware that exploited these UEFI/BIOS flaws. The malware could be implanted as part of other infections or intrusions. 

It's not known how many HP devices are affected, but five of the flaws are already known to affect hundreds of HP business-oriented models, as the company detailed in a previous security bulletin. The identification of consumer models affected by any of these 16 flaws is still pending.

This story was earlier reported by Bleeping Computer.

How to update your HP BIOS/UEFI firmware

HP has made patches available to fix all these flaws. But because we don't know exactly which consumer models are affected, you'll have to check your machine yourself by going to the HP software-and-drivers support page

Once there, either type in your device's serial number or let the HP support website detect your model. From there, the support site will walk you through the download-and-installation process. HP has further BIOS-update instructions here.

Serious UEFI flaws

The flaws reside in the UEFI firmware that controls HP motherboards, the most basic form of software running computers. UEFI is the successor to the better-known BIOS system, but both function the same way. It's the software that responds when you press the power button, turning on the motherboard and activating the hard disk so that Windows, Linux or another operating system can load.

Because UEFI and BIOS operate "below" the primary operating system, antivirus software often can't detect malware infections or other problems with them. UEFI generally counters this with firmware-integrity checks during the boot-up sequence, but Binarly said that integrity checks wouldn't work in these cases.

"The active exploitation of all the discovered vulnerabilities can't be detected by firmware integrity monitoring systems due to limitations of the Trusted Platform Module (TPM) measurement," said the blog post, which further explained that Microsoft's Secure Boot process could also be bypassed.

In other words, you may never know whether a bad actor has infected your system firmware. Better to take pre-emptive action and make sure it can't happen by installing the above updates. 

You'll also want to install some of the best Windows antivirus software to prevent first-stage infections that could lead to exploitation of these HP flaws.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
half-life alyx
Latest Half-Life 3 rumors point to a 2025 release — and maybe pigs will fly
NFL Sunday Ticket logo for YouTube
NFL Sunday Ticket 2025 pricing revealed — and it's bad news