Vendor
A local vulnerability in InsydeH2O UEFI firmware allows an attacker to execute arbitrary code at the firmware level, potentially enabling platform-wide persistence.