Use After Free Vulnerability in EDK II by TianoCore
CVE-2019-14586
8HIGH
What is CVE-2019-14586?
The EDK II component within the TianoCore firmware framework is susceptible to a use after free vulnerability. This flaw can be exploited by an authenticated user to gain elevated privileges, disclose sensitive information, or initiate a denial of service attack through adjacent access. Proper understanding and mitigation of this vulnerability are crucial for maintaining system integrity and security.
Affected Version(s)
Extensible Firmware Interface Development Kit (EDK II) EDK II