Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11098

Опубликовано: 08 мая 2019
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

An improper input validation flaw in the MdeModulePkg module of edk2 may allow an unauthenticated attacker with physical access to the system handled by edk2 to escalate his privileges and cause a denial of service or disclose information.

Отчет

Within Red Hat Enterprise Linux, edk2 is used only on virtualized systems, thus in this context the attacker needs to be a local user of the host system who have already the ability to compromise the guests systems. For this reason, this flaw has a Low Impact on both Red Hat Enterprise Linux 7 and 8.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ovmfOut of support scope
Red Hat Enterprise Linux 8edk2Affected
Red Hat Enterprise Linux 9edk2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2007434edk2: Insufficient input validation in MdeModulePkg may lead to privilege escalation

EPSS

Процентиль: 17%
0.00054
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 4 лет назад

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

CVSS3: 6.8
nvd
больше 4 лет назад

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

CVSS3: 6.8
debian
больше 4 лет назад

Insufficient input validation in MdeModulePkg in EDKII may allow an un ...

suse-cvrf
около 3 лет назад

Security update for ovmf

suse-cvrf
около 3 лет назад

Security update for ovmf

EPSS

Процентиль: 17%
0.00054
Низкий

6.4 Medium

CVSS3