Insufficient Memory Write Check in EDK II by Intel
CVE-2018-12182

6.7MEDIUM

What is CVE-2018-12182?

The vulnerability in EDK II involves an insufficient memory write check within the System Management Mode (SMM) service, which can be exploited by an authenticated user. This flaw could potentially lead to escalation of privileges, unauthorized information disclosure, or denial of service when accessed locally. Timely remediation is essential to safeguard systems against potential exploitation.

Affected Version(s)

Extensible Firmware Interface Development Kit (EDK II)

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.