CVE-2022-44611

HIGHCVSS 8/10EPSS 0.35%

Last modified

CVE-2022-44611 is a high-severity vulnerability rated 8/10 on the CVSS scale. Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.

Metrics

CVSS 3.1
8/10

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.35%

26.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelCeleron J6413 FirmwareAll versions
IntelCeleron N6211 FirmwareAll versions
IntelPentium J6425 FirmwareAll versions
IntelPentium N6415 FirmwareAll versions
IntelAtom X6211e FirmwareAll versions
IntelAtom X6413e FirmwareAll versions
IntelAtom X6425e FirmwareAll versions
IntelAtom X6212re FirmwareAll versions
IntelAtom X6414re FirmwareAll versions
IntelAtom X6425re FirmwareAll versions
IntelAtom X6427fe FirmwareAll versions
IntelAtom X6200fe FirmwareAll versions
IntelXeon W-1350 FirmwareAll versions
IntelXeon W-1350p FirmwareAll versions
IntelXeon W-1370 FirmwareAll versions
IntelXeon W-1370p FirmwareAll versions
IntelXeon W-1390 FirmwareAll versions
IntelXeon W-1390p FirmwareAll versions
IntelXeon W-1390t FirmwareAll versions
IntelCore I9-8950hk FirmwareAll versions
IntelCore I7-8557u FirmwareAll versions
IntelCore I7-8665ue FirmwareAll versions
IntelCore I7-8569u FirmwareAll versions
IntelCore I7-8665u FirmwareAll versions
IntelCore I7-8500y FirmwareAll versions
IntelCore I7-8565u FirmwareAll versions
IntelCore I7-8706g FirmwareAll versions
IntelCore I7-8086k FirmwareAll versions
IntelCore I7-8559u FirmwareAll versions
IntelCore I7-8700 FirmwareAll versions
IntelCore I7-8700b FirmwareAll versions
IntelCore I7-8700t FirmwareAll versions
IntelCore I7-8750h FirmwareAll versions
IntelCore I7-8850h FirmwareAll versions
IntelCore I7-8705g FirmwareAll versions
IntelCore I7-8709g FirmwareAll versions
IntelCore I7-8809g FirmwareAll versions
IntelCore I7\+8700 FirmwareAll versions
IntelCore I7-8700k FirmwareAll versions
IntelCore I7-8550u FirmwareAll versions
IntelCore I7-8650u FirmwareAll versions
IntelCore I5-8260u FirmwareAll versions
IntelCore I5-8257u FirmwareAll versions
IntelCore I5-8365ue FirmwareAll versions
IntelCore I5-8279u FirmwareAll versions
IntelCore I5-8365u FirmwareAll versions
IntelCore I5-8310y FirmwareAll versions
IntelCore I5-8210y FirmwareAll versions
IntelCore I5-8200y FirmwareAll versions
IntelCore I5-8265u FirmwareAll versions

Showing 50 of 298 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-44611?
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
How severe is CVE-2022-44611?
CVE-2022-44611 has a CVSS score of 8/10 (HIGH severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2022-44611?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-44611?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST