Heap Buffer Overflow in Tcg2MeasurePeImage
CVE-2022-36764

7.8HIGH

Key Information:

Vendor

Tianocore

Status
Vendor
CVE Published:
9 January 2024

What is CVE-2022-36764?

The EDK2 software project is affected by a vulnerability in the Tcg2MeasurePeImage() function, which exposes systems to potential heap buffer overflow attacks. This flaw can be triggered by a local user through a network, leading to severe risks regarding the confidentiality, integrity, and availability of the system. Attackers can exploit this vulnerability to manipulate software operations and possibly execute arbitrary code, highlighting the necessity for timely updates and security assessments in environments utilizing EDK2.

Affected Version(s)

edk2 * <= 202311

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doug Flick
.