Vulnerability Name: | CVE-2018-12182 (CCN-161214) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2018-06-11 | ||||||||||||||||||||||||||||||||||||
Published: | 2019-03-27 | ||||||||||||||||||||||||||||||||||||
Updated: | 2019-04-11 | ||||||||||||||||||||||||||||||||||||
Summary: | Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-441 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-12182 Source: BID Type: UNKNOWN 107648 Source: CCN Type: EDK2 Security Advisory SW SMI CONFUSED DEPUTY SMRAMSAVESTATE.C Source: CONFIRM Type: Patch, Vendor Advisory https://edk2-docs.gitbooks.io/security-advisory/content/sw-smi-confused-deputy-smramsavestate_c.html Source: XF Type: UNKNOWN tianocore-cve201812182-priv-esc(161214) Source: FEDORA Type: UNKNOWN FEDORA-2019-d47a9d4b8b Source: CONFIRM Type: UNKNOWN https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us Source: CCN Type: Lenovo Security Advisory: LEN-25869 TianoCore EDK II BIOS Vulnerabilities Source: CCN Type: IBM Security Bulletin 958911 (Flex System x280) IBM has released Unified Extensible Firmware Interface (UEFI) fixes in response to TianoCore EDK II BIOS Vulnerability (CVE-2018-12182) Source: CCN Type: TianoCore Web site TianoCore EDK II Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-12182 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |