7.8
CVSSv3

CVE-2022-36763

Published: 09/01/2024 Updated: 13/03/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Description<!---->A heap buffer overflow flaw was found via the Tcg2MeasureGptTable() function in EDK2, arising from inadequate validation of the GPT Primary Header, presenting a minor risk to confidentiality and integrity. The primary consequence is likely a crash or denial of service. This issue may allow a local malicious user to craft a GPT table, causing an integer overflow and consequent buffer overflow.A heap buffer overflow flaw was found via the Tcg2MeasureGptTable() function in EDK2, arising from inadequate validation of the GPT Primary Header, presenting a minor risk to confidentiality and integrity. The primary consequence is likely a crash or denial of service. This issue may allow a local malicious user to craft a GPT table, causing an integer overflow and consequent buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tianocore edk2

Vendor Advisories

Debian Bug report logs - #1060408 edk2: CVE-2022-36763 CVE-2022-36764 CVE-2022-36765 Package: src:edk2; Maintainer for src:edk2 is Debian QEMU Team &lt;pkg-qemu-devel@listsaliothdebianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Wed, 10 Jan 2024 19:48:02 UTC Severity: important Tags: security, upstrea ...
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability (CVE-2022-36763) EDK2 is susceptible to a vulnerability in the Tcg2MeasurePe ...
Description<!---->A heap buffer overflow flaw was found via the Tcg2MeasureGptTable() function in EDK2, arising from inadequate validation of the GPT Primary Header, presenting a minor risk to confidentiality and integrity The primary consequence is likely a crash or denial of service This issue may allow a local attacker to craft a GPT table, ca ...