CVE-2024-1298: Tianocore EDK2

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

Affected products

Published 2024-05-30. Last modified 2026-06-17.