CVE-2024-22448

Administrator-triggered service interruption via out-of-bounds write

Published Apr 10, 2024 · Updated Aug 1, 2024

Out-of-bounds write in Dell Client Platform BIOS allows local administrators to interrupt affected systems through a privileged local action. Dell has not disclosed the affected BIOS component, attacker-controlled input, or operation that writes beyond its intended buffer. Exploitation requires local authenticated administrator privileges and high-complexity conditions; Dell reports denial of service and low integrity impact.

CVSS severity4.7
Medium
EPSS probability0.18%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Out-of-bounds write in Dell Client Platform BIOS allows local administrators to interrupt affected systems through a privileged local action. Dell has not disclosed the affected BIOS component, attacker-controlled input, or operation that writes beyond its intended buffer. Exploitation requires local authenticated administrator privileges and high-complexity conditions; Dell reports denial of service and low integrity impact.

The record

CVE
CVE-2024-22448
Published
Apr 10, 2024
Updated
Aug 1, 2024
Vendor
Dell Technologies
Product
Alienware m16 R1
Classifications
CWE-787, T1499
Attack vector
local
Privileges
admin

Timeline

How it unfolded

  1. Apr 10, 2024CVE publishedPublication date reported by the CVE source.
  2. Aug 1, 2024Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <1.13.0

What conditions does exploitation require?

Attack vectorlocal
Required privilegesadmin

What is affected?

Dell Technologies · Alienware m16 R1version=0 <1.13.0
Unity Technologies · Dell Precision 5750version=0 <1.29.0
Unity Technologies · Dell Latitude 5540version=0 <1.12.0
Dell · Dell Client Platform BIOSversion=N/A <1.13.0; version=N/A <1.14.0; version=N/A <1.16.0; version=N/A <1.28.0; version=N/A <1.29.0; version=N/A <1.31.0; version=N/A <1.31.1; version=N/A <1.31.10; version=N/A <1.31.11; version=N/A <1.31.12; version=N/A <1.31.13; version=N/A <1.31.14; version=N/A <1.31.15; version=N/A <1.31.16; version=N/A <1.31.2; version=N/A <1.31.3; version=N/A <1.31.4; version=N/A <1.31.5; version=N/A <1.31.6; version=N/A <1.31.7; version=N/A <1.31.8; version=N/A <1.31.9
Unity Technologies · Dell OptiPlex Micro 7010 / Dell OptiPlex Micro Plus 7010version=0 <1.13.1
Unity Technologies · Dell Inspiron 7400version=0 <1.32.0
Unity Technologies · Dell OptiPlex Tower 7010 / Dell OptiPlex Tower Plus 7010version=0 <1.13.1
Unity Technologies · Dell Latitude 5310 2-in-1version=0 <1.23.0
Unity Technologies · Dell Latitude 7340version=0 <1.13.0
Unity Technologies · XPS 17 9730version=0 <1.11.0
Unity Technologies · Dell Inspiron 7700 AIOversion=0 <1.27.0
Dell Technologies · Dell G15 5530version=0 <1.14.0
Unity Technologies · Dell Latitude 5340version=0 <1.12.0
Dell Technologies · Inspiron 3030 Small Desktopversion=0 <1.3.0
Unity Technologies · Dell Inspiron 5509version=0 <1.29.0
Dell Technologies · Alienware m18 R1version=0 <1.16.0
Unity Technologies · Dell Latitude 9330version=0 <1.19.0
Unity Technologies · Dell XPS 17 9700version=0 <1.24.0
Unity Technologies · Vostro 15 3530version=0 <1.10.0
Unity Technologies · Dell Latitude 7320version=- <1.34.0
Unity Technologies · Dell Vostro 5880version=0 <1.25.0
Unity Technologies · Precision 3581version=0 <1.12.0
Unity Technologies · Dell Latitude 9420version=0 <1.29.0
Unity Technologies · Dell OptiPlex Small Form Factor 7010 / Dell OptiPlex Small Form Factor Plus 7010version=0 <1.13.1
Unity Technologies · Dell Latitude 9430version=- <1.22.0
Unity Technologies · Dell Inspiron 7300version=- <1.32.0
Unity Technologies · Vostro 14 3430version=0 <1.10.0
Dell Technologies · Dell G15 5511version=0 <1.28.0
Unity Technologies · Precision 5570version=0 <1.22.0
Unity Technologies · Dell Latitude 7520version=0 <1.34.0
Unity Technologies · Dell Vostro 5502version=- <1.29.0
Unity Technologies · Dell XPS 13 9315 2-in-1version=0 <1.15.0
Dell Technologies · Dell G16 7620version=0 <1.14.0
Unity Technologies · Dell Latitude 7420version=- <1.34.0
Unity Technologies · Dell Vostro 5402version=0 <1.29.0
Unity Technologies · Precision 3571version=0 <1.22.0
Unity Technologies · Dell Latitude 5531version=- <1.22.0
Dell Technologies · Inspiron 13 5330version=0 <1.14.0
Unity Technologies · Dell Latitude 9440 2-in-1version=0 <1.10.0
Unity Technologies · Dell Vostro 5301version=0 <1.32.0
Unity Technologies · Precision 5770version=0 <1.24.0
Unity Technologies · Dell Precision 3440 Small Form Factorversion=0 <1.25.0
Unity Technologies · Precision 3580version=0 <1.12.0
Unity Technologies · Dell Latitude 5330version=0 <1.321.0
Unity Technologies · Precision 3660 Towerversion=- <2.13.0
Unity Technologies · Vostro 3030Sversion=0 <1.3.0
Dell Technologies · Alienware m15 R6version=0 <1.29.0
Unity Technologies · Dell Latitude 5310version=0 <1.23.0

Published CVSS scores

4.4NVDCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
4.7DellCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesadmin
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-787Out-of-bounds Write
T1499Endpoint Denial of Service

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo