Logic Flaw in EDK II Could Allow Privilege Escalation by Authenticated User
CVE-2019-14575

7.8HIGH

Key Information:

Vendor

Tianocore

Vendor
CVE Published:
23 November 2020

What is CVE-2019-14575?

A logic issue exists in the DxeImageVerificationHandler() function of EDK II, which can be exploited by an authenticated user. This vulnerability could allow the attacker to escalate privileges through local access. The flaw arises from improper handling of image verification processes, leading to potential unauthorized actions that could compromise system integrity. Organizations utilizing EDK II should apply relevant security updates to mitigate this risk.

Affected Version(s)

Extensible Firmware Interface Development Kit (EDK II) EDK II

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.