CVE-2022-4020

HIGH

Acer Notebook - Privilege Escalation

Title source: llm
STIX 2.1

Description

Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.

Scores

CVSS v3 8.1
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (5)
acer/aspire_a115-21_firmware
acer/aspire_a315-22_firmware
acer/aspire_a315-22g_firmware
acer/extensa_ex215-21_firmware
acer/extensa_ex215-21g_firmware
Published Nov 28, 2022
Tracked Since Feb 18, 2026