LOW · 3.8

CVE-2022-38076

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

Vulnerability Description

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Score

3.8

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
IntelKiller< 34.22.1163
IntelProset\/Wireless Wifi< 22.200
IntelUefi Firmware< 3.2.20.23023
IntelDual Band Wireless-Ac 3165-
IntelDual Band Wireless-Ac 3168-
IntelDual Band Wireless-Ac 8260-
IntelDual Band Wireless-Ac 8265-
IntelKiller Wireless-Ac 1550-
IntelWireless-Ac 9260-
IntelWireless-Ac 9461-
IntelWireless-Ac 9462-
IntelWireless-Ac 9560-
IntelWireless 7265 \(Rev D\)-
FedoraprojectFedora37
DebianDebian Linux10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-38076?

CVE-2022-38076 is a vulnerability with a CVSS score of 3.8 (LOW). Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

How severe is CVE-2022-38076?

CVE-2022-38076 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-38076?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Killer, Intel Proset\/Wireless Wifi, Intel Uefi Firmware, Intel Dual Band Wireless-Ac 3165, Intel Dual Band Wireless-Ac 3168.