CVE-2019-14575 — Incorrect Authorization in Linux
Severity
7.8HIGHNVD
EPSS
0.1%
top 81.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 24
Description
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages1 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSAâ–¶
GHSA-jg74-g2r7-p8mf: Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access↗2022-05-24
OSVâ–¶
CVE-2019-14575: Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access↗2020-11-23
CVEListâ–¶
CVE-2019-14575: Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access↗2020-11-23
📋Vendor Advisories
3💬Community
3Bugzillaâ–¶
CVE-2019-14575 edk2: DxeImageVerificationHandler() fails open in case of dbx signature check [epel-all]↗2020-02-10
Bugzillaâ–¶
CVE-2019-14575 edk2: DxeImageVerificationHandler() fails open in case of dbx signature check [fedora-all]↗2020-02-10
Bugzillaâ–¶
CVE-2019-14575 edk2: DxeImageVerificationHandler() fails open in case of dbx signature check↗2019-08-02