6.8
CVSSv3

CVE-2019-11098

Published: 14/07/2021 Updated: 20/07/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tianocore edk ii -

Vendor Advisories

Debian Bug report logs - #991495 edk2: CVE-2019-11098 Package: src:edk2; Maintainer for src:edk2 is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 25 Jul 2021 19:12:02 UTC Severity: important Tags: security, upstream Found in version edk2/20201 ...