Buffer Overflow in EDK II Network Package
CVE-2023-45234
8.8HIGH
What is CVE-2023-45234?
The EDK2's Network Package, developed by TianoCore, is affected by a buffer overflow vulnerability that occurs when processing the DNS Servers option from DHCPv6 Advertise messages. If exploited, this flaw could enable an attacker to gain unauthorized access, resulting in potential impacts on confidentiality, integrity, and availability of affected systems. Mitigation measures should be taken as soon as possible to safeguard against potential attacks leveraging this vulnerability.
Affected Version(s)
edk2 edk2-stable202308
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Quarkslab Vulnerability Reports Team
Doug Flick