First published: Wed Mar 27 2019(Updated: )
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Credit: secure@intel.com secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tianocore EDK II | ||
debian/edk2 | 2020.11-2+deb11u2 2022.11-6+deb12u1 2024.05-2 |
https://edk2-docs.gitbooks.io/security-advisory/content/sw-smi-confused-deputy-smramsavestate_c.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12182 refers to an insufficient memory write check vulnerability in the SMM service for EDK II.
CVE-2018-12182 has a severity rating of medium with a CVSS score of 6.7.
CVE-2018-12182 affects the Tianocore Edk Ii software version and may allow an authenticated user to enable privilege escalation, information disclosure, and/or denial of service through local access.
An authenticated user can potentially exploit CVE-2018-12182 through local access to enable privilege escalation, information disclosure, and/or denial of service.
Yes, it is recommended to apply the latest security patches or updates provided by Tianocore for the Edk Ii software.