Null Pointer Dereference in Tianocore EDK2 Affects Local User Privileges
CVE-2019-14584

7.8HIGH

Key Information:

Vendor

Tianocore

Vendor
CVE Published:
3 June 2021

What is CVE-2019-14584?

A null pointer dereference vulnerability in Tianocore EDK2 can be exploited by an authenticated user with local access, potentially allowing for privilege escalation. This flaw might enable malicious actions that compromise system security, thus emphasizing the need for timely updates and robust access controls.

Affected Version(s)

Tianocore EDK2 See reference

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.