CVE Published: 27/03/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: intel |
Vendor: Extensible Firmware Interface Development Kit (EDK II) |
Product: Extensible Firmware Interface Development Kit (EDK II) Status : PUBLISHED
CVE-2018-12182 Description
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
CWE-ID: CWE Name: Escalation of Privilege, Information Disclosure and/or Denial of Service Source: Extensible Firmware Interface Development Kit (EDK II)
Common Attack Pattern Enumeration and Classification (CAPEC)