CVE-2022-4574

Severity
6.7MEDIUM
EPSS
0.0%
top 93.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30

Description

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages48 packages

🔴Vulnerability Details

2
CVEList
CVE-2022-4574: An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to2023-10-30
GHSA
GHSA-fm9f-7rqx-chvx: An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to2023-10-30
CVE-2022-4574 (MEDIUM CVSS 6.7) | An SMI handler input validation vul | cvebase.io