Vulnerability Name: | CVE-2014-4860 (CCN-95168) | ||||||||||||
Assigned: | 2014-08-07 | ||||||||||||
Published: | 2014-08-07 | ||||||||||||
Updated: | 2020-02-07 | ||||||||||||
Summary: | Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase. | ||||||||||||
CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-4860 Source: CCN Type: US-CERT VU#552286 UEFI EDK2 Capsule Update vulnerabilities Source: MISC Type: Third Party Advisory, US Government Resource http://www.kb.cert.org/vuls/id/552286 Source: CCN Type: BID-69123 EDK2 Capsule Update Mechanism CVE-2014-4860 Multiple Local Integer Overflow Vulnerabilities Source: CCN Type: UEFI Web site EDK2 Capsule Update mechanism Source: XF Type: UNKNOWN edk2-cve20144860-overflow(95168) Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-4860 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |