VDB
CVE-2022-33986
CVE-2022-33986
PUBLISHED
In der Insyde UEFI Firmware existieren mehrere "Time-of-Check to Time-of-Use (TOCTOU)" Schwachstellen. Ein lokaler Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.
EPSS 0.04% · 12.0th percentile
Risk Scores
EPSS Score
0.04%
12.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| HP | HP Computer | |
| Insyde | Insyde UEFI Firmware |
Timeline
- Nov 14, 2022 CVE Published
- Nov 15, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 23, 2023 EPSS Score
- May 5, 2023 EPSS Score
- Jun 17, 2023 EPSS Score
- Jul 30, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
- Oct 23, 2023 EPSS Score
- Dec 5, 2023 EPSS Score