First published: Mon Nov 28 2022(Updated: )
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
Credit: security@eset.com
Affected Software | Affected Version | How to fix |
---|---|---|
Acer Aspire A315-22g Firmware | ||
Acer Aspire A315-22g | ||
Acer Aspire A115-21 Firmware | ||
Acer Aspire A115-21 | ||
Acer Aspire A315-22 Firmware | ||
Acer Aspire A315-22 | ||
Acer Extensa Ex215-21 Firmware | ||
Acer Extensa Ex215-21 | ||
Acer Extensa Ex215-21g Firmware | ||
Acer Extensa Ex215-21g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4020 is a vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices.
CVE-2022-4020 may allow an attacker with elevated privileges to modify UEFI Secure Boot settings on Acer Aspire A315-22g Firmware.
No, Acer Aspire A315-22g is not vulnerable to CVE-2022-4020.
CVE-2022-4020 has a severity rating of 8.2 (high).
Acer has released a security update to address the vulnerability. Please refer to the following link for more information: [link](https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings)