cbcvebase.
CVE-2014-4860
published 2020-01-31

CVE-2014-4860: Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically…

medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.

Affected

4 ranges
VendorProductVersion rangeFixed in
american_megatrends_incorporatedbios
appleos_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20
debianedk2
phoenix_technologies_ltdsct3

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.8MEDIUM