CVE-2014-4859

EUVD-2014-4778
Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
tianocoreedk2
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
edk2
bookworm
2022.11-6+deb12u1
fixed
bookworm (security)
2022.11-6+deb12u1
fixed
bullseye
2020.11-2+deb11u2
fixed
bullseye (security)
2020.11-2+deb11u2
fixed
sid
2024.08-4
fixed
trixie
2024.08-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
edk2
precise
dne
trusty
dne
vivid
not-affected