CVE-2022-32766
published 2023-05-10CVE-2022-32766: Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.2th percentile
Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | gitpod-io_gitpod | >= 0 < 2022.11.3 | 2022.11.3 |
| intel | compute_stick_stk2mv64cc_firmware | < ccsklm5v.0067 | ccsklm5v.0067 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Gitpod vulnerable to Cross-site Scripting
ghsa·2023-06-05
CVE-2023-32766 [MEDIUM] CWE-79 Gitpod vulnerable to Cross-site Scripting
Gitpod vulnerable to Cross-site Scripting
Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:).
GHSA
GHSA-qg2q-896c-h92q: Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access
ghsa_unreviewed·2023-05-10
CVE-2022-32766 [HIGH] CWE-20 GHSA-qg2q-896c-h92q: Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access
Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-10
Published