CVE-2022-31637

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 367

Summary

CVE-2022-31637 is a newly discovered vulnerability affecting the BIOS of certain HP PCs. This issue involves potential time-of-check to time-of-use (TOCTOU) inconsistencies, which could lead to arbitrary code execution, privilege escalation, denial of service, and information disclosure. TOCTOU vulnerabilities occur when a system checks a condition at one point in time and then uses that condition at a later point without re-verification, enabling attackers to manipulate the system's state. HP is actively working on a software update to address this issue and users are encouraged to install it as soon as it becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP