ZeroHour

CVE-2023-45232

CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

Vendors
tianocore
Products
edk2
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news