Record summary

CVE-2022-21894 has a selected CVSS score of 4.4 (medium); EIP currently links 5 repository PoCs.

Description

Secure Boot Security Feature Bypass Vulnerability.

Description source: GitHub Advisory

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 1, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
5

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 1, 2023 · Source: CVE List

Affected products and versions

Showing 12 of 20
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List10.0.10240.0 to < 10.0.10240.19177affected
CVE List10.0.14393.0 to < 10.0.14393.4886affected
CVE List10.0.17763.0 to < 10.0.17763.2452affected
10.0.0 to < 10.0.17763.2452affected
CVE List10.0.0 to < 10.0.18363.2037affected
CVE List10.0.0 to < 10.0.19042.1466affected
CVE List10.0.0 to < 10.0.19043.1466affected
CVE List10.0.19043.0 to < 10.0.19044.1466affected
CVE List10.0.0 to < 10.0.22000.434affected
CVE List6.3.0 to < 6.3.9600.20246affected
CVE List6.2.9200.0 to < 6.2.9200.23584affected

Windows Server 2012 (Server Core installation)

Browse Microsoft / Windows Server 2012 (Server Core installation)
CVE List6.2.9200.0 to < 6.2.9200.23584affected

Proofs of concept

5

Repository PoCs

GitHubASkyeye/CVE-2022-21894-PayloadRepository PoCby ASkyeyeStars: 15Not analyzed7 files

22.9 KiB

GitHub

PoC details
GitHubWack0/batondrop_armv7Repository PoCby Wack0Stars: 10Not analyzed12 files

24.4 KiB

GitHub

PoC details
GitHubbakedmuffinman/BlackLotusDetectionRepository PoCby bakedmuffinmanStars: 0Not analyzed2 files

2.7 KiB

GitHub

PoC details
GitHubqjawls2003/BlackLotus-DetectionRepository PoCby qjawls2003Stars: 0Not analyzed2 files

2.0 KiB

GitHub

PoC details
GitHubnova-master/CVE-2022-21894-Payload-NewRepository PoCby nova-masterStars: 4Not analyzed13 files

117.5 KiB

GitHub

PoC details

References

3