Vulnerability Name: | CCN-158190 | ||||||
Published: | 2019-03-14 | ||||||
Updated: | 2019-03-14 | ||||||
Summary: | Multiple Lenovo products could allow a local attacker to gain elevated privileges on the system, caused by multiple buffer validation and parsing vulnerabilities in the TianoCore EDK II BIOS. An attacker could exploit this vulnerability to escalate privileges or cause a denial of service condition. | ||||||
CVSS v3 Severity: | 8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||
CVSS v2 Severity: | 7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: XF Type: UNKNOWN lenovo-tianocoreedkiibios-priv-esc(158190) Source: CCN Type: Lenovo Security Advisory: LEN-22660 TianoCore EDK II BIOS Vulnerabilities | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |