REDHAT-BUG-1641433: Medium severity edk ii vulnerability
A logic error in MdeModulePkg in EDK II firmware may allow authenticated user to potentially bypass configuration access controls and escalate privileges via local access.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-authenticated-variable-bypass.html
Upstream Bug:
https://bugzilla.tianocore.org/showbug.cgi?id=415
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1641433?
The severity of REDHAT-BUG-1641433 is classified as high due to the potential for authenticated users to bypass configuration access controls.
How do I fix REDHAT-BUG-1641433?
To resolve REDHAT-BUG-1641433, update to the latest version of the TianoCore EDK II firmware that addresses this vulnerability.
Who is affected by REDHAT-BUG-1641433?
Users of TianoCore EDK II firmware who have authenticated access are affected by REDHAT-BUG-1641433.
What types of attacks can exploit REDHAT-BUG-1641433?
REDHAT-BUG-1641433 can potentially be exploited for privilege escalation and unauthorized access by authenticated users.
Is there a workaround for REDHAT-BUG-1641433?
Currently, there are no known effective workarounds for REDHAT-BUG-1641433; updating the firmware is the recommended action.