---
id: CVE-2024-38798
title: >-
  EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of
  Sensitive Information to an Unauthorized Actor” by local access
summary: >-
  EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of
  Sensitive Information to an Unauthorized Actor” by local access. Successful
  exploitation of this vulnerability will lead to 


  possible information disclosure …
severity: none
cwe:
  - CWE-200
published: '2025-12-09'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-38798'
references:
  - url: 'https://github.com/tianocore/edk2/security/advisories/GHSA-q2c6-37h5-7cwf'
    label: infosec@edk2.groups.io
tags:
  - nvd
epss: 0.00142
epssPercentile: 0.02957
ingestedAt: '2026-10-02T01:05:54.712Z'
---

## Overview

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to 

possible information disclosure or escalation of privilege

 and impact Confidentiality.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
