Time-of-Check to Time-of-Use Flaws in HP BIOS Systems
CVE-2022-31639
7.8HIGH
Summary
Time-of-check to time-of-use (TOCTOU) vulnerabilities were discovered in the BIOS of certain HP PC products. These vulnerabilities could potentially be exploited to execute arbitrary code, escalate privileges, induce denial of service, or disclose sensitive information. Security measures should be taken to protect systems from these risks, as they could compromise the integrity and confidentiality of user data.
Affected Version(s)
HP PC BIOS See HP Security Bulletin reference for affected versions.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved