CVE-2018-12179: High severity edk ii vulnerability
Published Mar 27, 2019
·Updated
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Affected Software
1 affected component
Tianocore EDK II
Remediation
Event History
Mar 27, 2019
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-12179.
2
What is the severity of CVE-2018-12179?
The severity of CVE-2018-12179 is high with a severity value of 7.8.
3
What is affected by CVE-2018-12179?
The Tianocore Edk II system firmware is affected by CVE-2018-12179.
4
How can an unauthenticated user potentially exploit CVE-2018-12179?
Improper configuration in the system firmware for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure, and/or denial of service via local access.
5
How can I fix CVE-2018-12179 vulnerability?
To fix CVE-2018-12179 vulnerability, it is recommended to update the system firmware for EDK II to a patched version provided by the vendor.