{"id":"CVE-2022-21198","title":"Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.","summary":"Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.","severity":"high","cvss":7.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H","cwe":["CWE-367","CWE-367"],"vendor":"intel","product":"celeron_1000m_firmware","affected":["celeron_1000m_firmware","celeron_1005m_firmware","celeron_1007u_firmware","celeron_1017u_firmware","celeron_1019y_firmware","celeron_1020e_firmware","celeron_1020m_firmware","celeron_1037u_firmware","celeron_1047ue_firmware","celeron_2955u_firmware","celeron_2957u_firmware","celeron_2970m_firmware","celeron_2980u_firmware","celeron_2981u_firmware","celeron_3755u_firmware","celeron_3765u_firmware","celeron_3855u_firmware","celeron_3865u_firmware","celeron_3867u_firmware","celeron_3955u_firmware","celeron_3965u_firmware","celeron_3965y_firmware","celeron_4205u_firmware","celeron_4305u_firmware","celeron_4305ue_firmware","celeron_5205u_firmware","celeron_5305u_firmware","celeron_6305_firmware","celeron_6305e_firmware","celeron_6600he_firmware","celeron_725c_firmware","celeron_7300_firmware","celeron_7305_firmware","celeron_787_firmware","celeron_797_firmware","celeron_807_firmware","celeron_807ue_firmware","celeron_827e_firmware","celeron_847_firmware","celeron_847e_firmware","celeron_857_firmware","celeron_867_firmware","celeron_877_firmware","celeron_887_firmware","celeron_927ue_firmware","celeron_b710_firmware","celeron_b720_firmware","celeron_b800_firmware","celeron_b810_firmware","celeron_b810e_firmware","celeron_b815_firmware","celeron_b820_firmware","celeron_b830_firmware","celeron_b840_firmware","celeron_g1610_firmware","celeron_g1610t_firmware","celeron_g1620_firmware","celeron_g1620t_firmware","celeron_g1630_firmware","celeron_g1820_firmware","celeron_g1820t_firmware","celeron_g1820te_firmware","celeron_g1830_firmware","celeron_g1840_firmware","celeron_g1840t_firmware","celeron_g1850_firmware","celeron_g3900_firmware","celeron_g3900e_firmware","celeron_g3900t_firmware","celeron_g3900te_firmware","celeron_g3902e_firmware","celeron_g3920_firmware","celeron_g3920t_firmware","celeron_g3930_firmware","celeron_g3930e_firmware","celeron_g3930t_firmware","celeron_g3930te_firmware","celeron_g3940_firmware","celeron_g3950_firmware","celeron_g440_firmware","celeron_g460_firmware","celeron_g465_firmware","celeron_g470_firmware","celeron_g4900_firmware","celeron_g4900t_firmware","celeron_g4920_firmware","celeron_g4930_firmware","celeron_g4930e_firmware","celeron_g4930t_firmware","celeron_g4932e_firmware","celeron_g4950_firmware","celeron_g5205u_firmware","celeron_g530_firmware","celeron_g5305u_firmware","celeron_g530t_firmware","celeron_g540_firmware","celeron_g540t_firmware","celeron_g550_firmware","celeron_g550t_firmware","celeron_g555_firmware"],"published":"2022-11-11","updated":"2026-08-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-21198","references":[{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00688.html","label":"secure@intel.com"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00688.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-686975.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd"],"epss":0.00146,"epssPercentile":0.04243,"ingestedAt":"2026-08-11T16:47:02.481Z","slug":"CVE-2022-21198","body":"## Overview\n\nTime-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.\n\n## Affected\n\n- `celeron_1000m_firmware`\n- `celeron_1005m_firmware`\n- `celeron_1007u_firmware`\n- `celeron_1017u_firmware`\n- `celeron_1019y_firmware`\n- `celeron_1020e_firmware`\n- `celeron_1020m_firmware`\n- `celeron_1037u_firmware`\n- `celeron_1047ue_firmware`\n- `celeron_2955u_firmware`\n- `celeron_2957u_firmware`\n- `celeron_2970m_firmware`\n- `celeron_2980u_firmware`\n- `celeron_2981u_firmware`\n- `celeron_3755u_firmware`\n- `celeron_3765u_firmware`\n- `celeron_3855u_firmware`\n- `celeron_3865u_firmware`\n- `celeron_3867u_firmware`\n- `celeron_3955u_firmware`\n- `celeron_3965u_firmware`\n- `celeron_3965y_firmware`\n- `celeron_4205u_firmware`\n- `celeron_4305u_firmware`\n- `celeron_4305ue_firmware`\n- `celeron_5205u_firmware`\n- `celeron_5305u_firmware`\n- `celeron_6305_firmware`\n- `celeron_6305e_firmware`\n- `celeron_6600he_firmware`\n- `celeron_725c_firmware`\n- `celeron_7300_firmware`\n- `celeron_7305_firmware`\n- `celeron_787_firmware`\n- `celeron_797_firmware`\n- `celeron_807_firmware`\n- `celeron_807ue_firmware`\n- `celeron_827e_firmware`\n- `celeron_847_firmware`\n- `celeron_847e_firmware`\n- `celeron_857_firmware`\n- `celeron_867_firmware`\n- `celeron_877_firmware`\n- `celeron_887_firmware`\n- `celeron_927ue_firmware`\n- `celeron_b710_firmware`\n- `celeron_b720_firmware`\n- `celeron_b800_firmware`\n- `celeron_b810_firmware`\n- `celeron_b810e_firmware`\n- `celeron_b815_firmware`\n- `celeron_b820_firmware`\n- `celeron_b830_firmware`\n- `celeron_b840_firmware`\n- `celeron_g1610_firmware`\n- `celeron_g1610t_firmware`\n- `celeron_g1620_firmware`\n- `celeron_g1620t_firmware`\n- `celeron_g1630_firmware`\n- `celeron_g1820_firmware`\n- `celeron_g1820t_firmware`\n- `celeron_g1820te_firmware`\n- `celeron_g1830_firmware`\n- `celeron_g1840_firmware`\n- `celeron_g1840t_firmware`\n- `celeron_g1850_firmware`\n- `celeron_g3900_firmware`\n- `celeron_g3900e_firmware`\n- `celeron_g3900t_firmware`\n- `celeron_g3900te_firmware`\n- `celeron_g3902e_firmware`\n- `celeron_g3920_firmware`\n- `celeron_g3920t_firmware`\n- `celeron_g3930_firmware`\n- `celeron_g3930e_firmware`\n- `celeron_g3930t_firmware`\n- `celeron_g3930te_firmware`\n- `celeron_g3940_firmware`\n- `celeron_g3950_firmware`\n- `celeron_g440_firmware`\n- `celeron_g460_firmware`\n- `celeron_g465_firmware`\n- `celeron_g470_firmware`\n- `celeron_g4900_firmware`\n- `celeron_g4900t_firmware`\n- `celeron_g4920_firmware`\n- `celeron_g4930_firmware`\n- `celeron_g4930e_firmware`\n- `celeron_g4930t_firmware`\n- `celeron_g4932e_firmware`\n- `celeron_g4950_firmware`\n- `celeron_g5205u_firmware`\n- `celeron_g530_firmware`\n- `celeron_g5305u_firmware`\n- `celeron_g530t_firmware`\n- `celeron_g540_firmware`\n- `celeron_g540t_firmware`\n- `celeron_g550_firmware`\n- `celeron_g550t_firmware`\n- `celeron_g555_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":43.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}