CVE-2022-31637
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-367
- Affected
- hp/zcentral 4r workstation firmware · hp/z1 all-in-one g3 workstation firmware · hp/elitebook 725 g4 firmware · hp/elitebook 745 g4 firmware · hp/elitebook 755 g4 firmware · hp/probook 645 g3 firmware · hp/probook 655 g3 firmware · hp/mt43 mobile thin client firmware · hp/elite x2 1012 g2 firmware · hp/elitebook 1040 g4 firmware · hp/elitebook 820 g4 firmware · hp/elitebook 828 g4 firmware · hp/elitebook 840 g4 firmware · hp/elitebook 848 g4 firmware · hp/elitebook 850 g4 firmware · hp/elitebook x360 1020 g2 firmware · hp/elitebook x360 1030 g2 firmware · hp/pro x2 612 g2 firmware · hp/probook 455 g4 firmware · hp/probook 640 g3 firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/us-en/document/ish_7149996-7150021-16/hpsbhf03814Broken Link, Vendor Advisory
- https://support.hp.com/us-en/document/ish_7149996-7150021-16/hpsbhf03814Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.