cbcvebase.
CVE-2017-5732
published 2018-10-16

CVE-2017-5732: edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c [REJECTED CVE] A vulnerability exists in EDK-2 within…

high7.8
edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c [REJECTED CVE] A vulnerability exists in EDK-2 within BaseUefiDecompressLib.c (MdePkg/Library/BaseUefiDecompressLib). An authenticated attacker could exploit this vulnerability by supplying a crafted file, potentially leading to privilege escalation. Package: edk2 (Red Hat Enterprise Linux 8) - Not affected

Affected

1 ranges
VendorProductVersion rangeFixed in
applemacos_mojave

CVSS provenance

ghsa7.8HIGH
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.