CVE-2022-0004

MEDIUMCVSS 6.8/10EPSS 0.27%

Last modified

CVE-2022-0004 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.

Description

Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.27%

17.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelCore I3-12100 Firmware< 16.0.15
IntelCore I3-12100f Firmware< 16.0.15
IntelCore I3-12100t Firmware< 16.0.15
IntelCore I3-12300t Firmware< 16.0.15
IntelCore I3-12300 Firmware< 16.0.15
IntelCore I5-12600t Firmware< 16.0.15
IntelCore I5-12600kf Firmware< 16.0.15
IntelCore I5-12600hx Firmware< 16.0.15
IntelCore I5-12600k Firmware< 16.0.15
IntelCore I5-12600h Firmware< 16.0.15
IntelCore I5-12600 Firmware< 16.0.15
IntelCore I5-12500t Firmware< 16.0.15
IntelCore I5-12500h Firmware< 16.0.15
IntelCore I5-12500 Firmware< 16.0.15
IntelCore I5-12450hx Firmware< 16.0.15
IntelCore I5-12450h Firmware< 16.0.15
IntelCore I5-12400t Firmware< 16.0.15
IntelCore I5-12400f Firmware< 16.0.15
IntelCore I5-12400 Firmware< 16.0.15
IntelCore I7-12700t Firmware< 16.0.15
IntelCore I7-12700kf Firmware< 16.0.15
IntelCore I7-12700k Firmware< 16.0.15
IntelCore I7-12700h Firmware< 16.0.15
IntelCore I7-12700f Firmware< 16.0.15
IntelCore I7-12700 Firmware< 16.0.15
IntelCore I7-12850hx Firmware< 16.0.15
IntelCore I7-12800hx Firmware< 16.0.15
IntelCore I7-12800h Firmware< 16.0.15
IntelCore I7-12650hx Firmware< 16.0.15
IntelCore I7-12650h Firmware< 16.0.15
IntelCore I9-12950hx Firmware< 16.0.15
IntelCore I9-12900t Firmware< 16.0.15
IntelCore I9-12900kf Firmware< 16.0.15
IntelCore I9-12900k Firmware< 16.0.15
IntelCore I9-12900hx Firmware< 16.0.15
IntelCore I9-12900hk Firmware< 16.0.15
IntelCore I9-12900h Firmware< 16.0.15
IntelCore I9-12900f Firmware< 16.0.15
IntelCore I9-12900 Firmware< 16.0.15
IntelCore I3-11100b Firmware< 15.0.40
IntelCore I3-11100he Firmware< 15.0.40
IntelCore I5-11260h Firmware< 15.0.40
IntelCore I5-11300h Firmware< 15.0.40
IntelCore I5-11320h Firmware< 15.0.40
IntelCore I5-11400 Firmware< 15.0.40
IntelCore I5-11400f Firmware< 15.0.40
IntelCore I5-11400h Firmware< 15.0.40
IntelCore I5-11400t Firmware< 15.0.40
IntelCore I5-11500 Firmware< 15.0.40
IntelCore I5-11500b Firmware< 15.0.40

Showing 50 of 398 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-0004?
Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
How severe is CVE-2022-0004?
CVE-2022-0004 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2022-0004?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-0004?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST