CVE-2018-12183Out-of-bounds Write in Firmware Interface Development KIT

Severity
6.8MEDIUMNVD
EPSS
0.1%
top 75.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateJul 29

Description

Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9pwx-jwwh-vx6f: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de2022-05-13
CVEList
CVE-2018-12183: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de2019-03-27
OSV
CVE-2018-12183: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de2019-03-27

📋Vendor Advisories

3
Ubuntu
EDK II vulnerabilities2024-07-29
Red Hat
edk2: stack overflow in DxeCore leads to privilege escalation2019-03-29
Debian
CVE-2018-12183: edk2 - Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potent...2018

💬Community

3
Bugzilla
CVE-2018-12183 edk2: stack overflow in DxeCore leads to privilege escalation2019-03-29
Bugzilla
CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [fedora-all]2019-03-29
Bugzilla
CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [epel-all]2019-03-29
CVE-2018-12183 — Out-of-bounds Write | cvebase