Vulnerability Description
Stack overflow vulnerability in Aspire E5-475G 's BIOS firmware, in the FpGui module, a second call to GetVariable services allows local attackers to execute arbitrary code in the UEFI DXE phase and gain escalated privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acer | Aspire E5-475G Firmware | 1.21 |
| Acer | Aspire E5-475G | - |
Related Weaknesses (CWE)
References
- https://acer.com/Not Applicable
- https://github.com/10TG/vulnerabilities/blob/main/Acer/CVE-2022-40080/CVE-2022-4ExploitThird Party Advisory
- https://acer.com/Not Applicable
- https://github.com/10TG/vulnerabilities/blob/main/Acer/CVE-2022-40080/CVE-2022-4ExploitThird Party Advisory
FAQ
What is CVE-2022-40080?
CVE-2022-40080 is a vulnerability with a CVSS score of 7.8 (HIGH). Stack overflow vulnerability in Aspire E5-475G 's BIOS firmware, in the FpGui module, a second call to GetVariable services allows local attackers to execute arbitrary code in the UEFI DXE phase and g...
How severe is CVE-2022-40080?
CVE-2022-40080 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40080?
Check the references section above for vendor advisories and patch information. Affected products include: Acer Aspire E5-475G Firmware, Acer Aspire E5-475G.