7.3

CVE-2022-34405

An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the system.

Data is provided by the National Vulnerability Database (NVD)
DellRealtek High Definition Audio Driver Version < 6.0.9433.1
   DellAlienware M15 Ryzen Edition R5 Version-
   DellG15 5515 Version-
DellRealtek High Definition Audio Driver Version < 6.0.9400.1
   DellAlienware M15 R6 Version-
   DellG15 5510 Version-
   DellG15 5511 Version-
DellRealtek High Definition Audio Driver Version < 6.0.9394.1
   DellAlienware Area 51m R1 Version-
   DellAlienware Area 51m R2 Version-
   DellAlienware Aurora R10 Version-
   DellAlienware Aurora R11 Version-
   DellAlienware Aurora R12 Version-
   DellAlienware Aurora R8 Version-
   DellAlienware Aurora R9 Version-
   DellAlienware M15 R1 Version-
   DellAlienware M15 R2 Version-
   DellAlienware M15 R3 Version-
   DellAlienware M15 R4 Version-
   DellAlienware M17 R1 Version-
   DellAlienware M17 R2 Version-
   DellAlienware M17 R3 Version-
   DellAlienware M17 R4 Version-
   DellG5 5000 Version-
   DellG5 5090 Version-
   DellG5 5590 Version-
   DellG7 7590 Version-
   DellG7 7790 Version-
DellRealtek High Definition Audio Driver Version < 6.0.9407.1
   DellG7 7500 Version-
   DellG7 7700 Version-
DellRealtek High Definition Audio Driver Version < 6.0.9388.1
   DellAlienware Aurora R13 Version-
   DellAlienware X15 R1 Version-
   DellAlienware X17 R1 Version-
DellRealtek High Definition Audio Driver Version < 6.0.9254.1
   DellG3 3590 Version-
DellRealtek High Definition Audio Driver Version < 6.0.9422.1
   DellG3 3500 Version-
   DellG5 5500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.179
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
security_alert@emc.com 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.