Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40080


Stack overflow vulnerability in Aspire E5-475G 's BIOS firmware, in the FpGui module, a second call to GetVariable services allows local attackers to execute arbitrary code in the UEFI DXE phase and gain escalated privileges.


Published

2023-02-16T20:15:15.110

Last Modified

2025-03-19T15:15:40.463

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System acer aspire_e5-475g_firmware 1.21 Yes
Hardware acer aspire_e5-475g - No

References