Vulnerability Description
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Killer | < 34.22.1163 |
| Intel | Proset\/Wireless Wifi | < 22.200 |
| Intel | Uefi Firmware | < 3.2.20.23023 |
| Intel | Dual Band Wireless-Ac 3165 | - |
| Intel | Dual Band Wireless-Ac 3168 | - |
| Intel | Dual Band Wireless-Ac 8260 | - |
| Intel | Dual Band Wireless-Ac 8265 | - |
| Intel | Killer Wireless-Ac 1550 | - |
| Intel | Wireless-Ac 9260 | - |
| Intel | Wireless-Ac 9461 | - |
| Intel | Wireless-Ac 9462 | - |
| Intel | Wireless-Ac 9560 | - |
| Intel | Wireless 7265 \(Rev D\) | - |
| Fedoraproject | Fedora | 37 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00766.hPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00043.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00766.hPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00043.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
FAQ
What is CVE-2022-38076?
CVE-2022-38076 is a vulnerability with a CVSS score of 3.8 (LOW). Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-38076?
CVE-2022-38076 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38076?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Killer, Intel Proset\/Wireless Wifi, Intel Uefi Firmware, Intel Dual Band Wireless-Ac 3165, Intel Dual Band Wireless-Ac 3168.