cbcvebase.
CVE-2022-37341
published 2024-05-16

CVE-2022-37341: Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Affected

9 ranges
VendorProductVersion rangeFixed in
intelethernet_adapter_complete_driver< 29.0.129.0.1
intelethernet_controller_i225-it_firmware< 1.871.87
intelethernet_controller_i225-lm_firmware< 1.871.87
intelethernet_controller_i225-v_firmware< 1.871.87
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3_azure_connect_fea
msrcmicrosoft_sql_server_2017_for_x64-based_systems
msrcmicrosoft_sql_server_2019_for_x64-based_systems
msrcmicrosoft_sql_server_2022_for_x64-based_systems

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH