CVE-2022-37019

MEDIUM

HP Elite and ProBook Firmware - Privilege Escalation and Code Execution

Title source: llm
STIX 2.1

Description

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

References (1)

Core 1

Scores

CVSS v3 6.8
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (26)
hp/elite_slice_firmware < 00.02.64
hp/elite_slice_for_meeting_rooms_firmware < 00.02.64
hp/elitebook_1040_g3_firmware < 01.62
hp/elitebook_820_g3_firmware < 01.62
hp/elitebook_828_g3_firmware < 01.62
hp/elitebook_840_g3_firmware < 01.62
hp/elitebook_848_g3_firmware < 01.62
hp/elitebook_850_g3_firmware < 01.62
hp/elitebook_folio_g1_firmware < 01.62
hp/elitedesk_800_35w_g2_desktop_mini_pc_firmware < 00.02.63
... and 16 more
Published Jun 10, 2024
Tracked Since Feb 18, 2026