CVE-2022-26861

Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.

Scoring

Severity
HIGH
CVSS base score
7.9
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS probability
0.04%
CWE
CWE-1038
Published
2022-09-06
Last modified
2026-05-27

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs