CVE-2022-26837
Description
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper input validation in BIOS firmware for select Intel 9th-11th Gen, Xeon, and Celeron processors may let a privileged local attacker escalate privileges.
Vulnerability
Improper input validation exists in the BIOS firmware for certain Intel processors, including 9th, 10th, and 11th Generation Intel Core processors, Intel Xeon E and W Series, Intel Celeron, Intel Pentium, and Intel Atom processors (C3000, P5000, P5300). This vulnerability can be exploited by a privileged user to potentially escalate privileges via local access. Affected BIOS versions are those prior to the updates released in February 2023 as per Intel-SA-00717 [1].
Exploitation
An attacker must already have privileged access to the system (e.g., kernel or administrative rights) and the ability to load arbitrary code or modify BIOS settings. The exploitation requires local access to the machine, enabling the attacker to craft malicious inputs that bypass validation checks in the BIOS firmware, leading to code execution at a higher privilege level within the firmware or platform [1].
Impact
Successful exploitation allows the attacker to escalate privileges within the BIOS or platform firmware, potentially gaining control over low-level system functions, bypassing security mechanisms, and achieving persistent, stealthy control that persists across operating system reboots [1].
Mitigation
Intel released BIOS updates in February 2023 to address this issue. Affected users should update their system BIOS to the corrected versions provided by their device manufacturer. No workarounds are available. The vulnerability is not currently listed in KEV [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Intel/BIOS firmwaredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.