Integer Overflow Vulnerability in EDK II Affects TianoCore
CVE-2019-14562

5.5MEDIUM

Key Information:

Vendor

Tianocore

Vendor
CVE Published:
23 November 2020

What is CVE-2019-14562?

An integer overflow occurs in the DxeImageVerificationHandler() function of EDK II, which may allow authenticated users with local access to potentially execute a denial of service attack. This vulnerability highlights the need for robust error checking and input validation in security-critical components of the firmware.

Affected Version(s)

Extensible Firmware Interface Development Kit (EDK II) EDK II

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.