Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12182

Опубликовано: 28 мар. 2019
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ovmfNot affected
Red Hat Enterprise Linux 8edk2Not affected
Red Hat Virtualization 4redhat-virtualization-hostNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119->CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1694081edk2: insufficient memory write in SMM service leads to privilege escalation

EPSS

Процентиль: 28%
0.00097
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 6 лет назад

Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

CVSS3: 6.7
nvd
около 6 лет назад

Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

CVSS3: 6.7
debian
около 6 лет назад

Insufficient memory write check in SMM service for EDK II may allow an ...

CVSS3: 6.7
github
около 3 лет назад

Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

oracle-oval
больше 4 лет назад

ELSA-2020-5861: edk2 security update (IMPORTANT)

EPSS

Процентиль: 28%
0.00097
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2018-12182