Vulnerability Description
Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Celeron 1000M Firmware | - |
| Intel | Celeron 1000M | - |
| Intel | Celeron 1005M Firmware | - |
| Intel | Celeron 1005M | - |
| Intel | Celeron 1007U Firmware | - |
| Intel | Celeron 1007U | - |
| Intel | Celeron 1017U Firmware | - |
| Intel | Celeron 1017U | - |
| Intel | Celeron 1019Y Firmware | - |
| Intel | Celeron 1019Y | - |
| Intel | Celeron 1020E Firmware | - |
| Intel | Celeron 1020E | - |
| Intel | Celeron 1020M Firmware | - |
| Intel | Celeron 1020M | - |
| Intel | Celeron 1037U Firmware | - |
| Intel | Celeron 1037U | - |
| Intel | Celeron 1047Ue Firmware | - |
| Intel | Celeron 1047Ue | - |
| Intel | Celeron 2955U Firmware | - |
| Intel | Celeron 2955U | - |
Related Weaknesses (CWE)
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00688.Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00688.Vendor Advisory
FAQ
What is CVE-2022-21198?
CVE-2022-21198 is a vulnerability with a CVSS score of 7.9 (HIGH). Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-21198?
CVE-2022-21198 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-21198?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Celeron 1000M Firmware, Intel Celeron 1000M, Intel Celeron 1005M Firmware, Intel Celeron 1005M, Intel Celeron 1007U Firmware.