CVE-2022-36764 is a heap buffer overflow vulnerability in the Tcg2MeasurePeImage() function of EDK2, affecting tianocore edk2 products. This flaw carries a high CVSS score of 7.8, indicating that a local attacker can achieve high impact on confidentiality, integrity, and availability with low attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 202311CPE match | cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP BIOS - EDK II Reference Vulnerabilities
Nov 12, 2024HP BIOS - EDK II Reference Vulnerabilities
Nov 12, 2024CVE-2022-36764
Sep 10, 2024Insyde BIOS June 2024 EDK II Reference Vulnerabilities
Jun 18, 2024Insyde BIOS June 2024 EDK II Reference Vulnerabilities
Jun 18, 2024Heap Buffer Overflow in Tcg2MeasurePeImage
Jan 9, 2024EDK2: heap buffer overflow in Tcg2MeasurePeImage()
Jan 9, 2024