Heap Buffer Overflow in Tcg2MeasurePeImage
CVE-2022-36764

7HIGH

Key Information:

Vendor

Tianocore

Status
Vendor
CVE Published:
9 January 2024

What is CVE-2022-36764?

The EDK2 software project is affected by a vulnerability in the Tcg2MeasurePeImage() function, which exposes systems to potential heap buffer overflow attacks. This flaw can be triggered by a local user through a network, leading to severe risks regarding the confidentiality, integrity, and availability of the system. Attackers can exploit this vulnerability to manipulate software operations and possibly execute arbitrary code, highlighting the necessity for timely updates and security assessments in environments utilizing EDK2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

edk2 * <= 202311

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doug Flick
.