CVE-2022-37020: HP PC BIOS May 2024 Security Updates for Potential Stack Buffer Overflows

Published Jun 10, 2024
·
Updated

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

Affected Software

53 affected components
HP Pc Bios
All of the following
HP Elite Slice Firmware<00.02.64
HP Elite Slice
All of the following
HP Elite Slice For Meeting Rooms Firmware<00.02.64
HP Elite Slice For Meeting Rooms
All of the following
HP Elitebook 1040 G3 Firmware<01.62
HP Elitebook 1040 G3
All of the following
HP Elitebook 820 G3 Firmware<01.62
HP Elitebook 820 G3
All of the following
HP Elitebook 828 G3 Firmware<01.62
HP Elitebook 828 G3
All of the following
HP Elitebook 840 G3 Firmware<01.62
HP Elitebook 840 G3
All of the following
HP Elitebook 848 G3 Firmware<01.62
HP Elitebook 848 G3
All of the following
HP Elitebook 850 G3 Firmware<01.62
HP Elitebook 850 G3
All of the following
HP Elitebook Folio G1 Firmware<01.62
HP Elitebook Folio G1
All of the following
HP Elitedesk 800 35w G2 Desktop Mini Pc Firmware<00.02.63
HP Elitedesk 800 35w G2 Desktop Mini Pc
All of the following
HP Elitedesk 800 65w G2 Desktop Mini Pc Firmware<00.02.63
HP Elitedesk 800 65w G2 Desktop Mini Pc
All of the following
HP Mp9 G2 Retail System Firmware<02.63
HP Mp9 G2 Retail System
All of the following
HP Probook 440 G3 Firmware<1.62
HP Probook 440 G3
All of the following
HP Probook 446 G3 Firmware<1.62
HP Probook 446 G3
All of the following
HP Probook 470 G3 Firmware<1.62
HP Probook 470 G3
All of the following
HP Probook 640 G2 Firmware<1.62
HP Probook 640 G2
All of the following
HP Probook 650 G2 Firmware<1.62
HP Probook 650 G2
All of the following
HP Rp9 G1 Retail System Firmware<02.64
HP Rp9 G1 Retail System
All of the following
HP Z2 Mini G3 Workstation Firmware<01.91
HP Z2 Mini G3 Workstation
All of the following
HP Z238 Microtower Workstation Firmware<01.91
HP Z238 Microtower Workstation
All of the following
HP Z240 Small Form Factor Workstation Firmware<01.91
HP Z240 Small Form Factor Workstation
All of the following
HP Z240 Tower Workstation Firmware<01.91
HP Z240 Tower Workstation
All of the following
HP Zbook 15 G3 Firmware<1.62
HP Zbook 15 G3
All of the following
HP Zbook 15u G3 Firmware<1.62
HP Zbook 15u G3
All of the following
HP Zbook 17 G3 Firmware<1.62
HP Zbook 17 G3
All of the following
HP Zbook Studio G3 Firmware<1.62
HP Zbook Studio G3

Event History

Jun 10, 2024
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-37020?

CVE-2022-37020 has a high severity rating due to its potential to allow escalation of privileges and code execution.

2

How do I fix CVE-2022-37020?

To mitigate CVE-2022-37020, users should apply the latest firmware updates released by HP for affected PC BIOS.

3

Which products are affected by CVE-2022-37020?

CVE-2022-37020 affects certain HP PC products with vulnerable BIOS versions.

4

What types of vulnerabilities does CVE-2022-37020 involve?

CVE-2022-37020 involves potential privilege escalation and code execution vulnerabilities.

5

Is it necessary to update the firmware for CVE-2022-37020?

Yes, updating the firmware is necessary to protect against the vulnerabilities identified in CVE-2022-37020.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203