HIGH🇵🇱 Wersja polska

CVE-2022-40261

CVSS 8.2v3.1pub. 2022-09-20upd. 2025-05-28

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: OverClockSmiHandler SHA256: a204699576e1a48ce915d9d9423380c8e4c197003baf9d17e6504f0265f3039c Module GUID: 4698C2BD-A903-410E-AD1F-5EEF3A1AE422

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Ami Aptio V

    OS
    Ami
    5.0
  • Intel Nuc M15 Laptop Kit Lapbc510

    HW
    Intel
    all versions
  • Intel Nuc M15 Laptop Kit Lapbc510 Firmware

    OS
    Intel
    all versions
  • Intel Nuc M15 Laptop Kit Lapbc710

    HW
    Intel
    all versions
  • Intel Nuc M15 Laptop Kit Lapbc710 Firmware

    OS
    Intel
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-58770HIGH7.2same product

APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions ...

CVE-2025-33045HIGH8.2same product

APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and...

CVE-2025-22830HIGH7.3same product

APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A suc...

CVE-2024-42446HIGH7.5same product

APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race ...

CVE-2024-54084HIGH7.5same product

APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race ...