CVE-2018-3613: High severity edk ii vulnerability
A logic error in MdeModulePkg in EDK II firmware may allow authenticated user to potentially bypass configuration access controls and escalate privileges via local access.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-authenticated-variable-bypass.html
Upstream Bug:
https://bugzilla.tianocore.org/showbug.cgi?id=415
Other sources
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-3613.
What is the severity of CVE-2018-3613?
The severity of CVE-2018-3613 is high with a CVSS score of 7.8.
What is the affected software for CVE-2018-3613?
The affected software for CVE-2018-3613 includes ovmf version 0:20180508-6.gitee3198e672e2.el7, EDK II UDK2015, UDK2017, and UDK2018.
How does CVE-2018-3613 impact the system?
CVE-2018-3613 may allow an authenticated user to potentially enable escalation of privilege, information disclosure, and/or denial of service via local access.
Where can I find more information about CVE-2018-3613?
You can find more information about CVE-2018-3613 on the following references: [link1](https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-authenticated-variable-bypass.html), [link2](https://bugzilla.tianocore.org/show_bug.cgi?id=415), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1641435).