Vulnerability Description
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Killer | < 34.22.1163 |
| Intel | Proset\/Wireless Wifi | < 22.200 |
| Intel | Uefi Firmware | < 3.2.20.23023 |
| Intel | Killer Wi-Fi 6 Ax1650I\/S | - |
| Intel | Killer Wi-Fi 6E Ax1675I\/S | - |
| Intel | Killer Wi-Fi 6E Ax1675X\/W | - |
| Intel | Killer Wi-Fi 6E Ax1690I\/S | - |
| Intel | Killer Wireless-Ac 1550I\/S | - |
| Intel | Wi-Fi 6 Ax201 | - |
| Intel | Wi-Fi 6E Ax210 | - |
| Intel | Wi-Fi 6E Ax211 | - |
| Intel | Wi-Fi 6E Ax411 | - |
| Intel | Wireless-Ac 9461 | - |
| Intel | Wireless-Ac 9462 | - |
| Intel | Wireless-Ac 9560 | - |
| Fedoraproject | Fedora | 37 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00766.hPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00043.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00766.hPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00043.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
FAQ
What is CVE-2022-40964?
CVE-2022-40964 is a vulnerability with a CVSS score of 7.9 (HIGH). Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2022-40964?
CVE-2022-40964 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40964?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Killer, Intel Proset\/Wireless Wifi, Intel Uefi Firmware, Intel Killer Wi-Fi 6 Ax1650I\/S, Intel Killer Wi-Fi 6E Ax1675I\/S.