CVE-2022-34405

An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the system.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
dellCNA
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9433.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9400.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9394.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9407.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9388.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9254.1
dellrealtek_high_definition_audio_driver
𝑥
< 6.0.9422.1
𝑥
= Vulnerable software versions