ZeroHour

CVE-2022-4020

CVSS 3.1
8.2 high
EPSS
<1%p16
Published
()
Modified
Description

Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.

Vendors
acer
Products
aspire a315-22g firmware, aspire a115-21 firmware, aspire a315-22 firmware, extensa ex215-21 firmware, extensa ex215-21g firmware
Weakness
CWE-276
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news