CVE-2022-36765 is a high-severity vulnerability affecting EDK2, where an integer overflow in the CreateHob() function can lead to a buffer overflow. This flaw, with a CVSS score of 7.8, allows a local attacker to compromise confidentiality, integrity, and availability. While the vulnerability has no known active exploits, public exploit code, or significant community discussion, its potential impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 202311CPE match | cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP BIOS - EDK II Reference Vulnerabilities
Nov 12, 2024HP BIOS - EDK II Reference Vulnerabilities
Nov 12, 2024CVE-2022-36765
Sep 10, 2024Insyde BIOS June 2024 EDK II Reference Vulnerabilities
Jun 18, 2024Insyde BIOS June 2024 EDK II Reference Vulnerabilities
Jun 18, 2024Integer Overflow in CreateHob
Jan 9, 2024EDK2: integer overflow in CreateHob() could lead to HOB OOB R/W
Jan 9, 2024