CVE-2022-43777

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 12, 2023
Updated: Jan 6, 2025
CWE ID 367

Summary

CVE-2022-43777 is a newly disclosed vulnerability affecting the HP BIOS on specific HP PC models. This issue involves potential Time-of-Check to Time-of-Use (TOCTOU) bugs, which can result in arbitrary code execution, denial of service, or information disclosure. An attacker can exploit these vulnerabilities by manipulating the BIOS's input data during the transition from a check to a use operation. The exact impact and exploitability of these vulnerabilities are still under investigation, but it is recommended that affected users apply the forthcoming security updates to mitigate the risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hp Z8 G4 Workstation Firmware

Affected Vendors

  • HP