Cyber Resilience

CVE-2022-30704

High

Published: 16 February 2023

Published
16 February 2023
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS Score 0.0014 34.7th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-30704 is a high-severity Improper Initialization (CWE-665) vulnerability in Intel Core I7-1195G7 Firmware. Its CVSS base score is 7.2 (High).

Operationally, ranked at the 34.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

intel
core i7-11850he firmware
all versions
intel
core i7-11600h firmware
all versions
intel
core i7-11390h firmware
all versions
intel
core i7-1195g7 firmware
all versions
intel
core i7-11800h firmware
all versions
intel
core i7-11850h firmware
all versions
intel
core i7-11700 firmware
all versions
intel
core i7-11700f firmware
all versions
intel
core i7-11700k firmware
all versions
intel
core i7-11700kf firmware
all versions
+457 more product configuration(s) — see NVD for full list

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-665

Ensures shared resources are explicitly initialized or cleared on allocation, preventing exposure of prior contents to new users or processes.

addresses: CWE-665

Mandates that every instance begins in a known (presumably clean) state, eliminating reliance on residual or uninitialized state left by prior executions.

References