CVE-2019-14563: High severity Tianocore edk2 vulnerability
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14563?
CVE-2019-14563 is an integer truncation vulnerability in EDK II that may allow an authenticated user to potentially enable escalation of privilege via local access.
How severe is CVE-2019-14563?
CVE-2019-14563 has a severity rating of 7.8 (high).
Which software is affected by CVE-2019-14563?
The affected software includes EDK II versions 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, and 2023.05-2 on Debian, and version 0~20180205. on Ubuntu.
How can I fix CVE-2019-14563 on Debian?
To fix CVE-2019-14563 on Debian, update the edk2 package to one of the following versions: 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, or 2023.05-2.
How can I fix CVE-2019-14563 on Ubuntu?
To fix CVE-2019-14563 on Ubuntu, update the edk2 package to version 0~20180205.