PT-2019-6169 · Intel+5 · Edk Ii+5

CVE-2019-11098

·

Publicado

2019-03-12

·

Atualizado

2023-01-06

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EDKII (affected versions not specified)
Description The issue is related to insufficient input validation in the MdeModulePkg component of EDKII, which may allow an unauthenticated user with physical access to potentially enable escalation of privilege, denial of service, and/or information disclosure. This could lead to unauthorized access to confidential data, disruption of data integrity, and service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2021-1056
ALT-PU-2021-1057
ALT-PU-2021-1058
ALT-PU-2021-2871
ALT-PU-2021-2872
BDU:2022-01653
CVE-2019-11098
OESA-2022-1986
OESA-2022-1987
OESA-2022-1988
SUSE-SU-2023:0004-1
SUSE-SU-2023:0036-1
SUSE-SU-2023_0004-1
SUSE-SU-2023_0036-1
USN-5088-1

Produtos afetados

Alt Linux
Astra Linux
Edk Ii
Linuxmint
Suse
Ubuntu