Vulnerability Name: | CVE-2014-4859 (CCN-95169) | ||||||||||||
Assigned: | 2014-08-07 | ||||||||||||
Published: | 2014-08-07 | ||||||||||||
Updated: | 2020-02-06 | ||||||||||||
Summary: | Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data. | ||||||||||||
CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-4859 Source: CCN Type: US-CERT VU#552286 UEFI EDK2 Capsule Update vulnerabilities Source: MISC Type: Third Party Advisory, US Government Resource http://www.kb.cert.org/vuls/id/552286 Source: CCN Type: BID-69114 EDK2 Capsule Update Mechanism CVE-2014-4859 Local Integer Overflow Vulnerability Source: CCN Type: UEFI Web site EDK2 Capsule Update mechanism Source: XF Type: UNKNOWN edk2-cve-20144859-bo(95169) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |