CVE-2019-11098: Input Validation
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11098?
CVE-2019-11098 is a vulnerability in MdeModulePkg in EDKII that allows an unauthenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via physical access.
How severe is CVE-2019-11098?
CVE-2019-11098 has a severity value of 6.8, which is classified as medium severity.
What is affected by CVE-2019-11098?
The vulnerability affects Tianocore Edk II.
How can an unauthenticated user exploit CVE-2019-11098?
An unauthenticated user can potentially exploit CVE-2019-11098 by gaining physical access to the affected system.
Are there any references available for CVE-2019-11098?
Yes, you can find additional information about CVE-2019-11098 at the following reference: [link](https://edk2-docs.gitbook.io/security-advisory/bootguard-toctou-vulnerability)