CVE-2022-31635

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 367

Summary

CVE-2022-31635 is a newly discovered vulnerability affecting the BIOS of certain HP PCs. This issue involves potential time-of-check to time-of-use (TOCTOU) inconsistencies, which could result in arbitrary code execution, privilege escalation, denial of service, and information disclosure. Attackers may exploit this vulnerability by manipulating data at the wrong time, leading to unintended consequences and potential security breaches. HP is working on releasing patches to mitigate the risks associated with this vulnerability. Users are strongly encouraged to apply these updates as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP