s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-22297

📛 CVE Title

CVE-2023-22297

Description

Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

Overview

State
PUBLISHED
Assigner (CNA)
intel
CVSS severity
HIGH
CVSS score
CVSS 8.2 / 10 8.2 8.2 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Effective score
8.2 / 10 HIGH source: CNA overview
CWE(s)
CWE-788
Reserved
2023-02-15
Published
2023-05-10 15:17 UTC
Last updated
2025-01-27 19:03 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/22xxx/CVE-2023-22297.json
Linked Threat
CVE-2023-22297 — CVE-2023-22297

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-26461
Assigner
intel
Published
May 10, 2023, 1:17:03 PM
Updated
Jan 27, 2025, 6:03:42 PM
EUVD base score (CVSS 3.1)
8.2 / 10
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EUVD-reported EPSS
0.0400
Vendors
n/a
Products
Intel(R) Server Board BMC firmware (before version 2.90)
Aliases
GHSA-v5rx-7rr8-5mq3

ENISA description: Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
n/a Intel(R) Server Board BMC firmware before version 2.90 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (15)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:learn.microsoft.com

    As of November 11, 2025, Home and Pro editions of Windows 11, version 23H2 have reached end of servicing. Enterprise and Education editions of version 23H2 will continue to receive monthly security updates until November 10, 2026.

    2026-06-05 00:17 UTC
  • web:krebsonsecurity.com

    Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already ...

    2026-06-05 00:17 UTC
  • web:www.acronis.com

    Microsoft created Patch Tuesday to simplify updates by making them consistent and easy to plan around. But with cyberthreats continually expanding in volume and severity, it's becoming more difficult for any vendor to make patching easy.

    2026-06-05 00:17 UTC
  • web:www.windowscentral.com

    Another out of band update has been issued to Windows 11 users to address a major bug that caused Outlook to become inoperable after January's disastrous Patch Tuesday updates.

    2026-06-05 00:17 UTC
  • web:www.windowscentral.com

    Microsoft has posted an online bulletin confirming that the company is investigating reports that state Windows 11's latest security update has rendered some PCs unbootable.

    2026-06-05 00:17 UTC
  • web:www.cisa.gov

    Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287

    2026-05-22 05:48 UTC
  • web:www.computerworld.com

    Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

    2026-05-22 05:48 UTC
  • web:www.pcworld.com

    This month's Patch Tuesday includes an actively exploited Office zero-day vulnerability and several critical RCE bugs in Windows and Remote Desktop.

    2026-05-22 05:48 UTC
  • web:www.rapid7.com

    Microsoft has published 172 new vulnerabilities, including six zero-day vulnerabilities. Windows 10 moves past the end of support, sort of. Critical RCE in Windows Server Update Service.

    2026-05-22 05:48 UTC
  • web:www.techrepublic.com

    Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.

    2026-05-22 05:48 UTC
  • web:www.bleepingcomputer.com

    ThreatLocker Patch Management is built to tackle this reality head-on, providing security teams with greater control, visibility, and confidence over patching workflows — without compromising ...

    2026-05-22 05:48 UTC
  • web:cybersecuritynews.com

    Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.

    2026-05-22 05:48 UTC
  • web:krebsonsecurity.com

    October's Patch Tuesday also marks the final month that Microsoft will ship security updates for Windows 10 systems.

    2026-05-22 05:48 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 05:48 UTC
  • web:blog.qualys.com

    Microsoft's February 2026 Patch Tuesday focuses on closing security gaps that attackers could exploit, reinforcing the importance of timely patching in enterprise environments. Here's a quick breakdown of what you need to know. Microsoft Patch Tuesday for February 2026 This month's release addresses 61 vulnerabilities, including five critical and 52 important-severity vulnerabilities. In ...

    2026-05-22 05:48 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2023-22297.json.

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T10:07:06.107Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00839.html",
            "tags": [
              "x_transferred"
            ],
            "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00839.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-22297",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-01-27T17:27:37.351458Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-01-27T18:03:42.960Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Intel(R) Server Board BMC firmware",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "before version 2.90"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "escalation of privilege",
              "lang": "en"
            },
            {
              "cweId": "CWE-788",
              "description": "Access of memory location after end of buffer",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-05-10T13:17:03.477Z",
        "orgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
        "shortName": "intel"
      },
      "references": [
        {
          "name": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00839.html",
          "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00839.html"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
    "assignerShortName": "intel",
    "cveId": "CVE-2023-22297",
    "datePublished": "2023-05-10T13:17:03.477Z",
    "dateReserved": "2023-02-15T04:00:03.017Z",
    "dateUpdated": "2025-01-27T18:03:42.960Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}