← back
CVE-2022-36765

Integer Overflow in CreateHob

CVSS 7 HIGHEPSS 0.3%CWE-680
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
Affected products
TianoCore · edk2

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →