CVE-2022-32492: Input Validation
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32492?
CVE-2022-32492 is a vulnerability in Dell BIOS that allows a local authenticated malicious user to gain arbitrary code execution in SMRAM.
How can an attacker exploit CVE-2022-32492?
An attacker can exploit CVE-2022-32492 by using an SMI to execute arbitrary code in SMRAM.
What is the severity of CVE-2022-32492?
CVE-2022-32492 has a severity rating of 8.8 (high).
Which Dell products are affected by CVE-2022-32492?
The affected Dell products are Dell BIOS versions up to 2.21.0 and versions up to 2.25.0.
How can I fix CVE-2022-32492?
To fix CVE-2022-32492, Dell users should update their BIOS to a version higher than 2.21.0 if running an affected version up to 2.21.0, and update to a version higher than 2.25.0 if running an affected version up to 2.25.0.