CVE-2022-31638

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 367

Summary

CVE-2022-31638 is a newly disclosed vulnerability affecting the BIOS of certain HP PC models. This issue involves potential time-of-check to time-of-use (TOCTOU) inconsistencies, which could lead to arbitrary code execution, privilege escalation, denial of service, and information disclosure. An attacker could exploit these vulnerabilities by manipulating the BIOS during the boot process, taking advantage of the TOCTOU condition to gain unauthorized access or cause system instability. HP recommends users to update their BIOS as soon as patches become available to mitigate the risks associated with this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP