Unlimited Recursion Vulnerability in EDK II by TianoCore
CVE-2021-28210

7.8HIGH

Key Information:

Vendor

Tianocore

Status
Vendor
CVE Published:
11 June 2021

What is CVE-2021-28210?

The vulnerabilities in EDK II presented by TianoCore arise from an unlimited recursion issue in the DxeCore module. This flaw can lead to potential system instability and exhaustion of stack resources, which may result in denial of service conditions on affected systems. For further details and discussion regarding the vulnerability, refer to the TianoCore Bugzilla report. Users are encouraged to assess their implementations and apply necessary mitigations to prevent exploitation.

Affected Version(s)

EDK II <= unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.