Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade edk2-ovmf | Oct 27, 2023 | Jun 3, 2021 |
| Debian | — | Upgrade edk2 | May 3, 2021 | May 3, 2021 |
| Redhat_linux | — | Upgrade edk2-aarch64Upgrade edk2-ovmf | Oct 27, 2023 | Jun 3, 2021 |
| Suse | — | Upgrade shim-susesignedUpgrade qemu-uefi-aarch64Upgrade ovmfUpgrade qemu-ovmf-x86_64-debugUpgrade ovmf-toolsUpgrade qemu-ovmf-x86_64Upgrade qemu-ovmf-ia32Upgrade shim | Dec 19, 2020 | Dec 18, 2020 |
| Ubuntu | — | Upgrade qemu-efi-aarch64Upgrade ovmfUpgrade qemu-efiUpgrade qemu-efi-arm | Jan 8, 2021 | Dec 18, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub