HIGH
edk2: improper configuration insystem firmware leads to privilege escalation
Published Mar 27, 2019
7.8
HIGHCVSS 3.0
EPSS 0.42%
Description
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Affected products
- Vendor Extensible Firmware Interface Development Kit (EDK II) Product Extensible Firmware Interface Development Kit (EDK II) Defaultunknown
Affected
- n/a
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Extensible Firmware Interface Development Kit (EDK II) | Extensible Firmware Interface Development Kit (EDK II) | unknown | Affected
|
No data.
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2018-12179 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1694072 Issue Tracking
- https://edk2-docs.gitbooks.io/security-advisory/content/opal-blocksid-setting-disabled-after-s3.html x_refsource_CONFIRMPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-4157 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQYVZRFEXSN3KS43AVH4D7QX553EZQYP/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2018-12179
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2018-12179
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-12179 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1694072 | Issue Tracking | |
| https://edk2-docs.gitbooks.io/security-advisory/content/opal-blocksid-setting-disabled-after-s3.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-4157 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQYVZRFEXSN3KS43AVH4D7QX553EZQYP/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-12179 | ||
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us | x_refsource_CONFIRM | |
| https://www.cve.org/CVERecord?id=CVE-2018-12179 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner intel
Published Mar 27, 2019
Updated Aug 5, 2024
Reserved Jun 11, 2018
Link CVE-2018-12179
CISA Vulnrichment
No data
GitHub
No data