CVE-2022-27541
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-27541 is a newly disclosed vulnerability affecting HP BIOS in specific HP PC models. This issue involves potential Time-of-Check to Time-of-Use (TOCTOU) vulnerabilities that could allow an attacker to execute arbitrary code, cause denial of service, or disclose sensitive information. The vulnerability stems from a flaw in the BIOS's handling of input data, which an attacker could manipulate to their advantage during the transition from checking to using the data. HP has released patches to address this issue, and users are urged to install them promptly to mitigate potential risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Hp Z8 G4 Workstation Firmware
Affected Vendors
- HP