Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5pm-xmgf-pjcq

Опубликовано: 13 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.

EPSS

Процентиль: 8%
0.00029
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
redhat
12 месяцев назад

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
nvd
12 месяцев назад

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
debian
12 месяцев назад

Improper input validation in XmlCli feature for UEFI firmware for some ...

CVSS3: 7.5
fstec
12 месяцев назад

Уязвимость функции XmlCli микропрограммного обеспечения UEFI процессоров Intel, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 8%
0.00029
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20