Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.
References
Link Resource
http://www.kb.cert.org/vuls/id/552286 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: certcc

Published: 2020-01-31T15:08:16

Updated: 2020-01-31T15:08:16

Reserved: 2014-07-10T00:00:00


Link: CVE-2014-4860

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-01-31T16:15:10.377

Modified: 2020-02-07T17:43:46.640


Link: CVE-2014-4860

JSON object: View

cve-icon Redhat Information

No data.

CWE