← Vulnerability feed

Vulnerability record · CVE-2022-38786 · published 14 November 2023

CVE-2022-38786: Intel battery life diagnostic tool improper access control vulnerability

Intel · Battery Life Diagnostic Tool

Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

7.8 CVSS 3.1 High EPSS 0.17% · top 94.6% CWE-284 · Improper access control
7.8CVSS 3.1 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-38786 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-35060Intel battery life diagnostic tool uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially e…EPSS 0.19%7.8CVE-2023-34430Intel battery life diagnostic tool uncontrolled search path element vulnerabilityUncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enab…EPSS 0.20%7.8CVE-2022-36278Intel battery life diagnostic tool vulnerabilityInsufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to po…EPSS 0.19%7.8CVE-2022-36398Intel battery life diagnostic tool uncontrolled search path element vulnerabilityUncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially en…EPSS 0.17%7.8CVE-2022-34153Intel battery life diagnostic tool vulnerabilityImproper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially ena…EPSS 0.20%7.8CVE-2020-12346Intel battery life diagnostic tool incorrect default permissions vulnerabilityImproper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an authenticated user to potential…EPSS 0.28%6.7CVE-2023-32662Intel battery life diagnostic tool improper authorization vulnerabilityImproper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potential…EPSS 0.23%6.7CVE-2023-30763Intel battery life diagnostic tool heap-based buffer overflow vulnerabilityHeap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privil…EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2022-38786), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.