Rewterz
Rewterz Threat Alert – LokiBot Malware – Active IOCs
September 12, 2022
Rewterz
Rewterz Threat Alert – Ryuk Ransomware – Active IOCs
September 12, 2022

Rewterz Threat Advisory – Multiple HP PC products Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2022-31642 CVSS:7.8
HP PC products could allow a local authenticated attacker to gain elevated privileges on the system, caused by a time-of-check to time-of-use flaw in the system BIOS. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges, execute arbitrary code, obtain sensitive or cause a denial of service condition.

CVE-2022-31641 CVSS:7.5
HP PC products could allow a local authenticated attacker to gain elevated privileges on the system, caused by a time-of-check to time-of-use flaw in the system BIOS. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges, execute arbitrary code, obtain sensitive or cause a denial of service condition.

CVE-2022-31640 CVSS:7.5
HP PC products could allow a local authenticated attacker to gain elevated privileges on the system, caused by a time-of-check to time-of-use flaw in the system BIOS. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges, execute arbitrary code, obtain sensitive or cause a denial of service condition.

Impact

  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2022-31642
  • CVE-2022-31641
  • CVE-2022-31640

Affected Vendors

HP

Affected Products

  • HP PC BIOS

Remediation

Refer to HP Security Advisory for patch, upgrade or suggested workaround information.
HP Security Advisory