CVE-2019-14575: High severity Tianocore edk2 vulnerability
Last updated 25 August 2025
Other sources
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14575?
CVE-2019-14575 is a logic issue in DxeImageVerificationHandler() for EDK II that may allow an authenticated user to potentially enable escalation of privilege via local access.
What is the severity of CVE-2019-14575?
The severity of CVE-2019-14575 is high with a severity value of 7.8.
Which software is affected by CVE-2019-14575?
The affected software is EDK II, specifically versions 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, and 2023.05-2 for Debian, as well as version 0~20180205.0 and 0~20190606.20 for Ubuntu.
How can an authenticated user exploit CVE-2019-14575?
An authenticated user may exploit CVE-2019-14575 by leveraging the logic issue in DxeImageVerificationHandler() for EDK II to potentially enable escalation of privilege via local access.
Where can I find more information about CVE-2019-14575?
More information about CVE-2019-14575 can be found at the following references: [https://bugzilla.tianocore.org/show_bug.cgi?id=1608](https://bugzilla.tianocore.org/show_bug.cgi?id=1608), [https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html](https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html), [https://launchpad.net/bugs/cve/CVE-2019-14575](https://launchpad.net/bugs/cve/CVE-2019-14575).