CVE-2024-38796: Tianocore EDK2
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
Affected products
- Tianocore EDK2
Published 2024-09-27. Last modified 2026-06-17.