CVE-2022-40250 Details
Description
An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ami.com/security-center/ | CVE | Vendor Advisory |
| https://www.binarly.io/advisories/BRLY-2022-016 | CVE | ExploitThird Party Advisory |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00712.html | CVE | Not ApplicableThird Party Advisory |
| https://www.ami.com/security-center/ | [email protected] | Vendor Advisory |
| https://www.binarly.io/advisories/BRLY-2022-016 | [email protected] | ExploitThird Party Advisory |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00712.html | [email protected] | Not ApplicableThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| intel nuc m15 laptop kit lapbc510 firmware | bc0074 |
CPE
Remediation
| |
| intel nuc m15 laptop kit lapbc510 | All versions |
CPE
Remediation
| |
| intel nuc m15 laptop kit lapbc710 firmware | bc0074 |
CPE
Remediation
| |
| intel nuc m15 laptop kit lapbc710 | All versions |
CPE
Remediation
| |
| ami aptio v | 5.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 24, 2022 | Initial Analysis | [email protected] |