6.7
CVE-2022-34302
- EPSS 1.09%
- Veröffentlicht 26.08.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:09:15
- Erkennungen
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Horizondatasys ≫ Uefi Bootloader Version < 2022-06-01
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 20h2
Microsoft ≫ Windows 10 Version 21h1
Microsoft ≫ Windows 10 Version 21h2
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 11 Version -
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Windows Server 2016 Version 20h2
Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Windows Server 2022 Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.09% | 0.62 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html
https://www.kb.cert.org/vuls/id/309662