← back
CVE-2022-38696criticalCWE-119

CVE-2022-38696

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
In short

A memory buffer overflow vulnerability exists in BootRom due to missing validation of payload size. An attacker can exploit this without special privileges, potentially causing system crash or unauthorized code execution during the boot process.

Technical detail

BootRom fails to validate payload size before writing to a fixed buffer, enabling stack/heap buffer overflow (CWE-119). Exploitation requires ability to supply a malicious payload during boot, with no privilege escalation needed; impact includes arbitrary code execution or denial of service.

Summary generated and translated by AI from the official description.
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H