Vulnerability CVE-2019-14584: Information

Description

Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: June 3, 2021
Modified: June 11, 2021
Error type identifier: CWE-476

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1889486
  • Issue Tracking
  • Patch
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:*
      End excliding
      2020-10-21