CVE-2022-26864: Input Validation
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26864?
CVE-2022-26864 is classified as a medium severity vulnerability that may allow for security control bypass.
How do I fix CVE-2022-26864?
To fix CVE-2022-26864, update your Dell BIOS to a version newer than the specified vulnerable versions.
Which Dell products are affected by CVE-2022-26864?
CVE-2022-26864 affects various Dell BIOS versions, including those for Alienware m15 R5, G15 5515, and Inspiron series, among others.
Can CVE-2022-26864 be exploited remotely?
No, CVE-2022-26864 requires local authentication, meaning an attacker must have local access to exploit the vulnerability.
What types of attacks can CVE-2022-26864 facilitate?
CVE-2022-26864 could facilitate bypassing security controls within the System Management Mode (SMM) of affected systems.