CVE-2019-14586: Use After Free
Last updated 25 August 2025
Other sources
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14586?
CVE-2019-14586 is a use after free vulnerability in EDK II that may allow an authenticated user to potentially enable escalation of privilege, information disclosure, and/or denial of service via adjacent access.
What software is affected by CVE-2019-14586?
The EDK II package versions 0~20180205, 0~20190606.20, 0~20200229.4, 0~20160408, and other specified Debian packages are affected.
What is the severity of CVE-2019-14586?
CVE-2019-14586 has a severity rating of 'high' with a severity value of 8.
How can an attacker exploit CVE-2019-14586?
An attacker can exploit CVE-2019-14586 by leveraging the use after free vulnerability in EDK II to potentially enable escalation of privilege, information disclosure, and/or denial of service via adjacent access.
How can I fix CVE-2019-14586?
To fix CVE-2019-14586, update the affected EDK II package versions to the specified remedial versions mentioned in the software statement.