yocto ▾
›
master ▾
›
vulnerability
›
CVE-2019-14575
Component Overview
Vulnerability Overview
Name
CVE-2019-14575
Source
NVD (
link
)
Debian (
link
)
Description
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
CWEs
Published Date
Nov 23, 2020
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.tianocore.org/show_bug.cgi?id=1608
Issue Tracking
https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html
Mailing List
https://bugzilla.tianocore.org/show_bug.cgi?id=1608
Issue Tracking
https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html
Mailing List
Analysis
#
Affected Component
Analysis
ovmf
Not Affected
Vulnerability Ratings
#
7.8
CVSSv31
4.6
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
edk2
buildroot
2025.02.x
edk2-stable202411
Not Affected
edk2
buildroot
master
edk2-stable202602
Not Affected
ovmf
yocto
kirkstone
edk2-stable202202
Not Affected
ovmf
yocto
scarthgap
edk2-stable202402
Not Affected