Summary
When entering a password, the password keystrokes are stored in a circular queue. This queue is not cleared after password entry, making it possible to snoop some or all of the password characters later by direct examination of the memory which was used as the circular queue, leading to possible information disclosure or escalation of privilege.
Impact
A successful exploit of this vulnerability may lead to a loss of Confidentiality.
Mitigation release plan
A patch was upstreamed into EDK2. e50d8f3
References
Original bugzilla ticket. https://bugzilla.tianocore.org/show_bug.cgi?id=4760
Summary
When entering a password, the password keystrokes are stored in a circular queue. This queue is not cleared after password entry, making it possible to snoop some or all of the password characters later by direct examination of the memory which was used as the circular queue, leading to possible information disclosure or escalation of privilege.
Impact
A successful exploit of this vulnerability may lead to a loss of Confidentiality.
Mitigation release plan
A patch was upstreamed into EDK2. e50d8f3
References
Original bugzilla ticket. https://bugzilla.tianocore.org/show_bug.cgi?id=4760