CVE-2022-33894

HIGH

Intel(R) Processors - Privilege Escalation

Title source: llm

Description

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-20
Status published

Affected Products (50)

intel/xeon_e-2314_firmware
intel/xeon_e-2324g_firmware
intel/xeon_e-2334_firmware
intel/xeon_e-2336_firmware
intel/xeon_e-2356g_firmware
intel/xeon_e-2374g_firmware
intel/xeon_e-2378_firmware
intel/xeon_e-2378g_firmware
intel/xeon_e-2386g_firmware
intel/xeon_e-2388g_firmware
intel/xeon_e-2226ge_firmware
intel/xeon_e-2254me_firmware
intel/xeon_e-2254ml_firmware
intel/xeon_e-2276me_firmware
intel/xeon_e-2276ml_firmware
... and 35 more

Timeline

Published May 10, 2023
Tracked Since Feb 18, 2026