CVE-2022-31639

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 367

Summary

CVE-2022-31639 is a newly discovered vulnerability affecting the BIOS of certain HP PCs. This issue involves potential time-of-check to time-of-use (TOCTOU) bugs, increasing the risk of arbitrary code execution, privilege escalation, denial of service, and information disclosure. The BIOS's susceptibility to these vulnerabilities could be exploited by malicious actors to gain unauthorized access and manipulate system operations. HP is working on releasing patches to mitigate this risk, and users are advised to install these updates promptly to secure their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP