PT-2019-6169 · Intel+5 · Edk Ii+5

Published

2019-03-12

·

Updated

2023-01-06

·

CVE-2019-11098

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EDKII (affected versions not specified)
Description The issue is related to insufficient input validation in the MdeModulePkg component of EDKII, which may allow an unauthenticated user with physical access to potentially enable escalation of privilege, denial of service, and/or information disclosure. This could lead to unauthorized access to confidential data, disruption of data integrity, and service disruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1056
ALT-PU-2021-1057
ALT-PU-2021-1058
ALT-PU-2021-2871
ALT-PU-2021-2872
BDU:2022-01653
CVE-2019-11098
OESA-2022-1986
OESA-2022-1987
OESA-2022-1988
SUSE-SU-2023:0004-1
SUSE-SU-2023:0036-1
SUSE-SU-2023_0004-1
SUSE-SU-2023_0036-1
USN-5088-1

Affected Products

Alt Linux
Astra Linux
Edk Ii
Linuxmint
Suse
Ubuntu