CVE-2022-27539

high-risk
Published 2023-06-12

Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.

Do I need to act?

-
0.17% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10 High
LOCAL / HIGH complexity

Affected Products (20)

Zcentral 4R Workstation Firmware
Z1 All-In-One G3 Workstation Firmware
Elitebook 725 G4 Firmware
Elitebook 745 G4 Firmware
Elitebook 755 G4 Firmware
Probook 645 G3 Firmware
Probook 655 G3 Firmware
Mt43 Mobile Thin Client Firmware
Elitebook 820 G4 Firmware
Elitebook 828 G4 Firmware
Elitebook 840 G4 Firmware
Elitebook 848 G4 Firmware
Elitebook 850 G4 Firmware
Elitebook X360 1020 G2 Firmware
Elitebook X360 1030 G2 Firmware
Pro X2 612 G2 Firmware
Probook 455 G4 Firmware
Probook 640 G3 Firmware

Affected Vendors

Hp
54
/ 100
high-risk
Severity 20/34 · Moderate
Exploitability 1/34 · Minimal
Exposure 33/34 · Critical