CVE-2019-14587: Medium severity Tianocore edk2 vulnerability
Last updated 25 August 2025
Other sources
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14587?
The severity of CVE-2019-14587 is medium with a CVSS score of 6.5.
How can an unauthenticated user exploit CVE-2019-14587?
An unauthenticated user can exploit CVE-2019-14587 to potentially enable denial of service through adjacent access.
Which software versions are affected by CVE-2019-14587?
The affected software versions include 0~20180205, 0~20190606.20, 0~20200229.4, 0~20160408, 0~20181115.85588389-3+deb10u3, 2020.11-2+deb11u1, 2022.11-6, 2023.05-2, Tianocore EDK2, and Debian Linux 9.0.
How can I mitigate CVE-2019-14587 on Ubuntu?
To mitigate CVE-2019-14587 on Ubuntu, ensure you have the recommended version of the 'edk2' package installed.
Where can I find more information about CVE-2019-14587?
You can find more information about CVE-2019-14587 on the following references: [Bugzilla](https://bugzilla.tianocore.org/show_bug.cgi?id=1989), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html), [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-14587).