CVE-2022-0004
Last modified
CVE-2022-0004 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Core I3-12100 Firmware | < 16.0.15 |
| Intel | Core I3-12100f Firmware | < 16.0.15 |
| Intel | Core I3-12100t Firmware | < 16.0.15 |
| Intel | Core I3-12300t Firmware | < 16.0.15 |
| Intel | Core I3-12300 Firmware | < 16.0.15 |
| Intel | Core I5-12600t Firmware | < 16.0.15 |
| Intel | Core I5-12600kf Firmware | < 16.0.15 |
| Intel | Core I5-12600hx Firmware | < 16.0.15 |
| Intel | Core I5-12600k Firmware | < 16.0.15 |
| Intel | Core I5-12600h Firmware | < 16.0.15 |
| Intel | Core I5-12600 Firmware | < 16.0.15 |
| Intel | Core I5-12500t Firmware | < 16.0.15 |
| Intel | Core I5-12500h Firmware | < 16.0.15 |
| Intel | Core I5-12500 Firmware | < 16.0.15 |
| Intel | Core I5-12450hx Firmware | < 16.0.15 |
| Intel | Core I5-12450h Firmware | < 16.0.15 |
| Intel | Core I5-12400t Firmware | < 16.0.15 |
| Intel | Core I5-12400f Firmware | < 16.0.15 |
| Intel | Core I5-12400 Firmware | < 16.0.15 |
| Intel | Core I7-12700t Firmware | < 16.0.15 |
| Intel | Core I7-12700kf Firmware | < 16.0.15 |
| Intel | Core I7-12700k Firmware | < 16.0.15 |
| Intel | Core I7-12700h Firmware | < 16.0.15 |
| Intel | Core I7-12700f Firmware | < 16.0.15 |
| Intel | Core I7-12700 Firmware | < 16.0.15 |
| Intel | Core I7-12850hx Firmware | < 16.0.15 |
| Intel | Core I7-12800hx Firmware | < 16.0.15 |
| Intel | Core I7-12800h Firmware | < 16.0.15 |
| Intel | Core I7-12650hx Firmware | < 16.0.15 |
| Intel | Core I7-12650h Firmware | < 16.0.15 |
| Intel | Core I9-12950hx Firmware | < 16.0.15 |
| Intel | Core I9-12900t Firmware | < 16.0.15 |
| Intel | Core I9-12900kf Firmware | < 16.0.15 |
| Intel | Core I9-12900k Firmware | < 16.0.15 |
| Intel | Core I9-12900hx Firmware | < 16.0.15 |
| Intel | Core I9-12900hk Firmware | < 16.0.15 |
| Intel | Core I9-12900h Firmware | < 16.0.15 |
| Intel | Core I9-12900f Firmware | < 16.0.15 |
| Intel | Core I9-12900 Firmware | < 16.0.15 |
| Intel | Core I3-11100b Firmware | < 15.0.40 |
| Intel | Core I3-11100he Firmware | < 15.0.40 |
| Intel | Core I5-11260h Firmware | < 15.0.40 |
| Intel | Core I5-11300h Firmware | < 15.0.40 |
| Intel | Core I5-11320h Firmware | < 15.0.40 |
| Intel | Core I5-11400 Firmware | < 15.0.40 |
| Intel | Core I5-11400f Firmware | < 15.0.40 |
| Intel | Core I5-11400h Firmware | < 15.0.40 |
| Intel | Core I5-11400t Firmware | < 15.0.40 |
| Intel | Core I5-11500 Firmware | < 15.0.40 |
| Intel | Core I5-11500b Firmware | < 15.0.40 |
Showing 50 of 398 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-0004?
How severe is CVE-2022-0004?
How do I fix CVE-2022-0004?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-0001Non-transparent sharing of branch predictor selectors betwee…6.5
- CVE-2022-0002Non-transparent sharing of branch predictor within a context…6.5
- CVE-2022-0003Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-0005Sensitive information accessible by physical probing of JTAG…2.4
- CVE-2022-0010Insertion of Sensitive Information into Log File vulnerabili…5.5
- CVE-2022-0011PAN-OS software provides options to exclude specific website…6.5
- CVE-2022-0012An improper link resolution before file access vulnerability…7.1
- CVE-2022-0013A file information exposure vulnerability exists in the Palo…5.5
- CVE-2022-0014An untrusted search path vulnerability exists in the Palo Al…7.3
Are you affected by CVE-2022-0004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
