CVE-2022-38396
Published on: Not Yet Published
Last Modified on: 04/25/2023 04:01:00 PM UTC
Certain versions of Windows 10 1507 from Microsoft contain the following vulnerability:
HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This potential vulnerability was remediated starting with Windows 10 versions 21H2 on October 31, 2021.
- CVE-2022-38396 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
HP Inc. - HP Factory Preinstalled Windows 10 20H2 Images version = See HP Security Bulletin reference for affected versions.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Potential Escalation of Privilege in HP Factory Preinstalled Windows 10 20H2 Images | HP® Customer Support | support.hp.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions …
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Microsoft | Windows 10 1507 | - | All | All | All |
Operating System | Microsoft | Windows 10 1511 | - | All | All | All |
Operating System | Microsoft | Windows 10 1607 | - | All | All | All |
Operating System | Microsoft | Windows 10 1703 | - | All | All | All |
Operating System | Microsoft | Windows 10 1709 | - | All | All | All |
Operating System | Microsoft | Windows 10 1803 | - | All | All | All |
Operating System | Microsoft | Windows 10 1807 | - | All | All | All |
Operating System | Microsoft | Windows 10 1809 | - | All | All | All |
Operating System | Microsoft | Windows 10 1909 | - | All | All | All |
Operating System | Microsoft | Windows 10 2004 | - | All | All | All |
Operating System | Microsoft | Windows 10 20h2 | - | All | All | All |
- cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1807:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-38396 : HP Factory Preinstalled Images on certain systems that shipped with #Windows 10 versions 20H2 and… twitter.com/i/web/status/1… | 2023-02-12 04:14:05 |