CVE Vulnerabilities

CVE-2019-14575

Published: Nov 23, 2020 | Modified: Jan 01, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
LOW

Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected Software

Name Vendor Start Version End Version
Edk2 Tianocore - (including) - (including)
Edk2 Ubuntu bionic *
Edk2 Ubuntu eoan *
Edk2 Ubuntu esm-apps/bionic *
Edk2 Ubuntu esm-apps/xenial *
Edk2 Ubuntu trusty *
Edk2 Ubuntu xenial *

References