Heap Buffer Overflow in Tcg2MeasureGptTable
CVE-2022-36763

7.8HIGH

Key Information:

Vendor

Tianocore

Status
Vendor
CVE Published:
9 January 2024

What is CVE-2022-36763?

A vulnerability exists within the Tcg2MeasureGptTable() function of EDK2, where inadequate validation can lead to a heap buffer overflow when triggered by a local user via the network. This flaw has the potential to compromise the confidentiality, integrity, and availability of systems utilizing affected versions of EDK2. Addressing this issue is critical for maintaining robust security in applications that rely on TianoCore's firmware.

Affected Version(s)

edk2 * <= 202311

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doug Flick
.