CVE-2022-37019: HP PC BIOS May 2024 Security Updates for Potential Stack Buffer Overflows
Published Jun 10, 2024
·Updated
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
Affected Software
53 affected components
HP Pc Bios
All of the following
HP Elite Slice Firmware<00.02.64
HP Elite Slice
All of the following
HP Elite Slice For Meeting Rooms Firmware<00.02.64
HP Elite Slice For Meeting Rooms
All of the following
HP Elitebook 1040 G3 Firmware<01.62
HP Elitebook 1040 G3
All of the following
HP Elitebook 820 G3 Firmware<01.62
HP Elitebook 820 G3
All of the following
HP Elitebook 828 G3 Firmware<01.62
HP Elitebook 828 G3
All of the following
HP Elitebook 840 G3 Firmware<01.62
HP Elitebook 840 G3
All of the following
HP Elitebook 848 G3 Firmware<01.62
HP Elitebook 848 G3
All of the following
HP Elitebook 850 G3 Firmware<01.62
HP Elitebook 850 G3
All of the following
HP Elitebook Folio G1 Firmware<01.62
HP Elitebook Folio G1
All of the following
HP Elitedesk 800 35w G2 Desktop Mini Pc Firmware<00.02.63
HP Elitedesk 800 35w G2 Desktop Mini Pc
All of the following
HP Elitedesk 800 65w G2 Desktop Mini Pc Firmware<00.02.63
HP Elitedesk 800 65w G2 Desktop Mini Pc
All of the following
HP Mp9 G2 Retail System Firmware<02.63
HP Mp9 G2 Retail System
All of the following
HP Probook 440 G3 Firmware<1.62
HP Probook 440 G3
All of the following
HP Probook 446 G3 Firmware<1.62
HP Probook 446 G3
All of the following
HP Probook 470 G3 Firmware<1.62
HP Probook 470 G3
All of the following
HP Probook 640 G2 Firmware<1.62
HP Probook 640 G2
All of the following
HP Probook 650 G2 Firmware<1.62
HP Probook 650 G2
All of the following
HP Rp9 G1 Retail System Firmware<02.64
HP Rp9 G1 Retail System
All of the following
HP Z2 Mini G3 Workstation Firmware<01.91
HP Z2 Mini G3 Workstation
All of the following
HP Z238 Microtower Workstation Firmware<01.91
HP Z238 Microtower Workstation
All of the following
HP Z240 Small Form Factor Workstation Firmware<01.91
HP Z240 Small Form Factor Workstation
All of the following
HP Z240 Tower Workstation Firmware<01.91
HP Z240 Tower Workstation
All of the following
HP Zbook 15 G3 Firmware<1.62
HP Zbook 15 G3
All of the following
HP Zbook 15u G3 Firmware<1.62
HP Zbook 15u G3
All of the following
HP Zbook 17 G3 Firmware<1.62
HP Zbook 17 G3
All of the following
HP Zbook Studio G3 Firmware<1.62
HP Zbook Studio G3
Event History
Jun 10, 2024
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-37019?
CVE-2022-37019 has a high severity level due to the potential for privilege escalation and code execution.
2
How do I fix CVE-2022-37019?
To address CVE-2022-37019, update your HP PC BIOS to the latest firmware version released by HP.
3
What HP products are affected by CVE-2022-37019?
CVE-2022-37019 affects certain HP PC products with vulnerable BIOS versions.
4
Can CVE-2022-37019 be exploited remotely?
CVE-2022-37019 typically requires local access to the system for exploitation.
5
What should I do if I cannot update my BIOS for CVE-2022-37019?
If unable to update the BIOS for CVE-2022-37019, consider implementing strong access controls to mitigate the risk.