CVE-2017-5731: Tianocore EDK2

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.

Affected products

  • Tianocore EDK2: before 2017-11-07 (fixed in 2017-11-07)

Published 2019-10-28. Last modified 2026-06-17.