CVE-2022-27538
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-367
- Affected
- hp/dragonfly folio g3 2-in-1 firmware · hp/elite dragonfly firmware · hp/elite dragonfly g3 firmware · hp/elite dragonfly g2 firmware · hp/elite dragonfly max firmware · hp/elite x2 1013 g3 firmware · hp/elite x2 g4 firmware · hp/elite x2 g8 tablet firmware · hp/elite x360 1040 g9 2-in-1 firmware · hp/elitebook 1040 g9 firmware · hp/elitebook 1050 g1 firmware · hp/elitebook 630 g9 firmware · hp/elitebook 640 g9 firmware · hp/elitebook 645 g9 firmware · hp/elitebook 650 g9 firmware · hp/elitebook 655 g9 firmware · hp/elitebook 735 g5 firmware · hp/elitebook 735 g6 firmware · hp/elitebook 745 g5 firmware · hp/elitebook 745 g6 firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/us-en/document/ish_7387020-7387107-16/hpsbhf03827Patch, Vendor Advisory
- https://support.hp.com/us-en/document/ish_7387020-7387107-16/hpsbhf03827Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.