CVE-2022-36374
published 2023-11-14CVE-2022-36374: Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to…
PriorityP426medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.18%
8.1th percentile
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | aptio_v_uefi_firmware_integrator_tools | — | — |
| intel | aptio_v_uefi_firmware_integrator_tools | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_oracle5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6j6r-mmfh-xf8p: Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5
ghsa_unreviewed·2023-11-14
CVE-2022-36374 [HIGH] CWE-284 GHSA-6j6r-mmfh-xf8p: Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Installation (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-10-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Installation (Apache Ant) — CVE-2021-36374
Oracle Oracle Retail Applications Risk Matrix: Installation (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle HealthCare Applications Risk Matrix: Health Policy Engine (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-07-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle HealthCare Applications Risk Matrix: Health Policy Engine (Apache Ant) — CVE-2021-36374
Oracle Oracle HealthCare Applications Risk Matrix: Health Policy Engine (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Installer, OSM SDK (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-04-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Installer, OSM SDK (Apache Ant) — CVE-2021-36374
Oracle Oracle Communications Applications Risk Matrix: Installer, OSM SDK (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Build Tool (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-01-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Build Tool (Apache Ant) — CVE-2021-36374
Oracle Oracle Communications Applications Risk Matrix: Build Tool (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-14
Published