CVE-2022-34405

An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exploit this vulnerability by waiting for an administrator to launch the application and attach to the process to elevate privileges on the system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:alienware_m15_ryzen_edition_r5:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g15_5515:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:alienware_m15_r6:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g15_5510:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g15_5511:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:alienware_area_51m_r1:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_area_51m_r2:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_aurora_r10:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_aurora_r11:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_aurora_r12:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_aurora_r8:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_aurora_r9:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m15_r1:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m15_r2:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m15_r3:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m15_r4:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m17_r1:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m17_r2:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m17_r3:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_m17_r4:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g5_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g5_5090:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g5_5590:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g7_7590:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g7_7790:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:g7_7500:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g7_7700:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:alienware_aurora_r13:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_x15_r1:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:alienware_x17_r1:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:g3_3590:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:a:dell:realtek_high_definition_audio_driver:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:g3_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g5_5500:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000205721/dsa-2022-316-dell-client-security-update-for-a-realtek-high-definition-audio-driver-vulnerability - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000205721/dsa-2022-316-dell-client-security-update-for-a-realtek-high-definition-audio-driver-vulnerability - Vendor Advisory
Summary
  • (es) Se identificó una vulnerabilidad de control de acceso inadecuado en Realtek audio driver. Un usuario malicioso autenticado local puede potencialmente explotar esta vulnerabilidad esperando a que un administrador inicie la aplicación y se conecte al proceso para elevar los privilegios en el sistema.

21 Jul 2023, 18:49

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-26 21:15

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34405

Mitre link : CVE-2022-34405

CVE.ORG link : CVE-2022-34405


JSON object : View

Products Affected

dell

  • realtek_high_definition_audio_driver
  • alienware_m17_r4
  • g5_5590
  • alienware_aurora_r12
  • alienware_m17_r2
  • alienware_aurora_r9
  • alienware_m15_r3
  • g3_3590
  • alienware_aurora_r8
  • alienware_m17_r1
  • g7_7700
  • g7_7790
  • alienware_m17_r3
  • g15_5510
  • alienware_aurora_r10
  • g3_3500
  • alienware_x15_r1
  • alienware_x17_r1
  • alienware_m15_r4
  • g7_7590
  • g15_5515
  • alienware_m15_r6
  • alienware_area_51m_r1
  • alienware_m15_r2
  • alienware_m15_r1
  • g15_5511
  • g5_5000
  • alienware_area_51m_r2
  • g7_7500
  • g5_5500
  • alienware_aurora_r13
  • alienware_m15_ryzen_edition_r5
  • g5_5090
  • alienware_aurora_r11
CWE
CWE-285

Improper Authorization

NVD-CWE-Other