CVE-2022-34405

EUVD-2022-37360
An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the system.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
dellCNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9433.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9400.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9394.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9407.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9388.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9254.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9422.1
𝑥
= Vulnerable software versions