CVE-2024-38798

MEDIUM

EDK2 < edk2-stable202511 - Exposure of Sensitive Information via Local Access

Title source: llm
STIX 2.1

Description

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.

References (1)

Core 1

Scores

CVSS v4 5.8
EPSS 0.0012
EPSS Percentile 2.1%
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
TianoCore/EDK2 < edk2-stable202511
Published Dec 09, 2025
Tracked Since Feb 18, 2026