Description
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
References (2)
Core 2
Core References
Patch x_refsource_misc
http://sourceforge.net/p/edk2/code/16280/
Third Party Advisory, US Government Resource x_refsource_misc
http://www.kb.cert.org/vuls/id/533140
Scores
CVSS v3
6.8
EPSS
0.0022
EPSS Percentile
44.3%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-120
Status
published
Products (1)
tianocore/edk2
< svn_16280
Published
Feb 06, 2020
Tracked Since
Feb 18, 2026