cbcvebase.
CVE-2019-14575
published 2020-11-23

CVE-2019-14575: Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianedk2< edk2 0~20200229.4c0f6e34-1 (bookworm)edk2 0~20200229.4c0f6e34-1 (bookworm)
tianocoreedk2>= 0 < 0~20200229.4c0f6e34-10~20200229.4c0f6e34-1
tianocoreedk2>= 0 < 0~20200229.4c0f6e34-10~20200229.4c0f6e34-1
tianocoreedk2>= 0 < 0~20200229.4c0f6e34-10~20200229.4c0f6e34-1
tianocoreedk2>= 0 < 0~20200229.4c0f6e34-10~20200229.4c0f6e34-1
tianocoreedk2>= 0 < 0~20160408.ffea0a2c-2ubuntu0.10~20160408.ffea0a2c-2ubuntu0.1
tianocoreedk2>= 0 < 0~20180205.c0d9813c-2ubuntu0.20~20180205.c0d9813c-2ubuntu0.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv9.1CRITICAL