CVE-2022-36764: Heap Buffer Overflow in Tcg2MeasurePeImage
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
Other sources
Heap Buffer Overflow in Tcg2MeasurePeImage
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36764?
CVE-2022-36764 is classified as a critical vulnerability due to its potential to compromise confidentiality, integrity, and availability.
How do I fix CVE-2022-36764?
To fix CVE-2022-36764, update to the latest version of the EDK2 package recommended by your operating system.
What type of vulnerability is CVE-2022-36764?
CVE-2022-36764 is a heap buffer overflow vulnerability that can be triggered via a local network.
What software is affected by CVE-2022-36764?
CVE-2022-36764 affects the EDK2 firmware developed by Tianocore.
Can CVE-2022-36764 be exploited remotely?
CVE-2022-36764 requires local network access for exploitation, making it a network-related vulnerability.