CVE-2022-32486: Input Validation
Published Oct 11, 2022
·Updated
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
Affected Software
5 affected components
Dell Bios<2.21.0
Dell Precision 5820 Tower
Dell Bios<2.25.0
Dell Precision 7820 Tower
Dell Precision 7920 Tower
Event History
Oct 11, 2022
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-32486?
CVE-2022-32486 is a vulnerability in Dell BIOS that allows a local authenticated malicious user to gain arbitrary code execution in SMRAM.
2
How severe is CVE-2022-32486?
CVE-2022-32486 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2022-32486?
Dell BIOS versions up to and excluding 2.21.0 and 2.25.0 are affected by CVE-2022-32486.
4
How can the CVE-2022-32486 vulnerability be exploited?
A local authenticated malicious user can exploit the CVE-2022-32486 vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
5
Is Dell Precision 5820 Tower affected by CVE-2022-32486?
No, Dell Precision 5820 Tower is not affected by CVE-2022-32486.