Lucene search

K
nvd[email protected]NVD:CVE-2022-40261
HistorySep 20, 2022 - 6:15 p.m.

CVE-2022-40261

2022-09-2018:15:10
CWE-120
web.nvd.nist.gov
3
elevate privileges
smm protections
install backdoor
bios
uefi firmware

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

17.8%

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: OverClockSmiHandler SHA256: a204699576e1a48ce915d9d9423380c8e4c197003baf9d17e6504f0265f3039c Module GUID: 4698C2BD-A903-410E-AD1F-5EEF3A1AE422

Affected configurations

Nvd
Node
intelnuc_m15_laptop_kit_lapbc510_firmwareMatch-
AND
intelnuc_m15_laptop_kit_lapbc510Match-
Node
intelnuc_m15_laptop_kit_lapbc710_firmwareMatch-
AND
intelnuc_m15_laptop_kit_lapbc710Match-
Node
amiaptio_vMatch5.0
VendorProductVersionCPE
intelnuc_m15_laptop_kit_lapbc510_firmware-cpe:2.3:o:intel:nuc_m15_laptop_kit_lapbc510_firmware:-:*:*:*:*:*:*:*
intelnuc_m15_laptop_kit_lapbc510-cpe:2.3:h:intel:nuc_m15_laptop_kit_lapbc510:-:*:*:*:*:*:*:*
intelnuc_m15_laptop_kit_lapbc710_firmware-cpe:2.3:o:intel:nuc_m15_laptop_kit_lapbc710_firmware:-:*:*:*:*:*:*:*
intelnuc_m15_laptop_kit_lapbc710-cpe:2.3:h:intel:nuc_m15_laptop_kit_lapbc710:-:*:*:*:*:*:*:*
amiaptio_v5.0cpe:2.3:o:ami:aptio_v:5.0:*:*:*:*:*:*:*

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

17.8%

Related for NVD:CVE-2022-40261