Back

MEDIUM

edk2: Insufficient input validation in MdeModulePkg may lead to privilege escalation

Published Jul 14, 2021

Description

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

Affected products

Remediation

Red Hat statement

Within Red Hat Enterprise Linux, edk2 is used only on virtualized systems, thus in this context the attacker needs to be a local user of the host system who have already the ability to compromise the guests systems. For this reason, this flaw has a Low Impact on both Red Hat Enterprise Linux 7 and 8.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner intel
Published Jul 14, 2021
Updated Aug 4, 2024
Reserved Apr 11, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 8, 2019