CVE-2022-27635
published 2023-08-11CVE-2022-27635: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of…
PriorityP425medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.24%
14.5th percentile
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firmware-nonfree | < firmware-nonfree 20240610-1 (forky) | firmware-nonfree 20240610-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| intel | killer | < 34.22.1163 | 34.22.1163 |
| intel | proset_wireless_wifi | < 22.200 | 22.200 |
| intel | uefi_firmware | < 3.2.20.23023 | 3.2.20.23023 |
| intel_proset | wireless_wifi_and_killer_wifi_software | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi
vendor_redhat·2023-08-08·CVSS 8.2
CVE-2022-27635 [HIGH] CWE-284 hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi
hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to enable escalation of privilege via local access.
Statement: Please contact your OEM support group to obtain the correct driver version.
Mitigation: UEFI firmware to version 3.2.20.23023 (includes versions 2.2.20.23023 and 1.2.20.23023)or later.
Debian
CVE-2022-27635: firmware-nonfree - Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) Wi...
vendor_debian·2022·CVSS 8.2
CVE-2022-27635 [HIGH] CVE-2022-27635: firmware-nonfree - Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) Wi...
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 20240610-1)
sid: resolved (fixed in 20240610-1)
trixie: resolved (fixed in 20240610-1)
OSV
CVE-2022-27635: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalati
osv·2023-08-11·CVSS 6.7
CVE-2022-27635 [MEDIUM] CVE-2022-27635: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalati
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
GHSA
GHSA-356g-gr7f-c28h: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalati
ghsa_unreviewed·2023-08-11
CVE-2022-27635 [MEDIUM] CWE-284 GHSA-356g-gr7f-c28h: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalati
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00766.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00043.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/HUCYUR4WBTELCRHELISJ3RMZVHKIV5TN/https://lists.fedoraproject.org/archives/list/[email protected]/message/K24OJT4AVMNND7LBTC2ZDDTE6DJHAKB4/https://lists.fedoraproject.org/archives/list/[email protected]/message/Y76A3PLHIQCEPESB4XVBV5SRRXQEZ5JY/http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00766.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00043.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/HUCYUR4WBTELCRHELISJ3RMZVHKIV5TN/https://lists.fedoraproject.org/archives/list/[email protected]/message/K24OJT4AVMNND7LBTC2ZDDTE6DJHAKB4/https://lists.fedoraproject.org/archives/list/[email protected]/message/Y76A3PLHIQCEPESB4XVBV5SRRXQEZ5JY/
2023-08-11
Published