CVE-2022-36763: Heap Buffer Overflow in Tcg2MeasureGptTable
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
Other sources
Heap Buffer Overflow in Tcg2MeasureGptTable
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36763?
CVE-2022-36763 is considered a critical vulnerability due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2022-36763?
To mitigate CVE-2022-36763, users should update to the latest version of the EDK2 software as specified in the advisories.
What systems are affected by CVE-2022-36763?
CVE-2022-36763 affects the Tianocore EDK2 firmware and various Linux distributions such as Ubuntu and Debian.
What is the nature of the vulnerability in CVE-2022-36763?
The vulnerability in CVE-2022-36763 involves a heap buffer overflow that can be triggered via a local network.
Can CVE-2022-36763 be exploited remotely?
Yes, CVE-2022-36763 can be exploited remotely due to its local network attack vector.