VYPR
Unrated severityNVD Advisory· Published Feb 16, 2023· Updated Jan 27, 2025

CVE-2022-26837

CVE-2022-26837

Description

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper input validation in BIOS firmware for select Intel 9th-11th Gen, Xeon, and Celeron processors may let a privileged local attacker escalate privileges.

Vulnerability

Improper input validation exists in the BIOS firmware for certain Intel processors, including 9th, 10th, and 11th Generation Intel Core processors, Intel Xeon E and W Series, Intel Celeron, Intel Pentium, and Intel Atom processors (C3000, P5000, P5300). This vulnerability can be exploited by a privileged user to potentially escalate privileges via local access. Affected BIOS versions are those prior to the updates released in February 2023 as per Intel-SA-00717 [1].

Exploitation

An attacker must already have privileged access to the system (e.g., kernel or administrative rights) and the ability to load arbitrary code or modify BIOS settings. The exploitation requires local access to the machine, enabling the attacker to craft malicious inputs that bypass validation checks in the BIOS firmware, leading to code execution at a higher privilege level within the firmware or platform [1].

Impact

Successful exploitation allows the attacker to escalate privileges within the BIOS or platform firmware, potentially gaining control over low-level system functions, bypassing security mechanisms, and achieving persistent, stealthy control that persists across operating system reboots [1].

Mitigation

Intel released BIOS updates in February 2023 to address this issue. Affected users should update their system BIOS to the corrected versions provided by their device manufacturer. No workarounds are available. The vulnerability is not currently listed in KEV [1].

References
  1. INTEL-SA-00717

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.