CVE-2014-4859: Integer Overflow
Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-4859?
CVE-2014-4859 is an integer overflow vulnerability in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2.
How does CVE-2014-4859 affect Tianocore EDK2?
CVE-2014-4859 affects Tianocore EDK2 and allows physically proximate attackers to bypass intended access restrictions via crafted data.
What is the severity of CVE-2014-4859?
The severity of CVE-2014-4859 is high, with a severity score of 6.8.
How can I fix CVE-2014-4859?
To fix CVE-2014-4859, apply the necessary security patches or updates provided by the software vendor.
Where can I find more information about CVE-2014-4859?
You can find more information about CVE-2014-4859 at the following reference: http://www.kb.cert.org/vuls/id/552286