6.7 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
An insecure default to allow UEFI Shell in EDK2 was …
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
References
Affected products
- <2023.05-2ubuntu0.1
Matching in nixpkgs
pkgs.edk2
Intel EFI development kit
pkgs.edk2-uefi-shell
UEFI Shell from Tianocore EFI development kit
pkgs.python311Packages.edk2-pytool-library
Python library package that supports UEFI development
-
nixos-unstable edk2-pytool-library-0.22.3
- nixpkgs-unstable edk2-pytool-library-0.22.3
- nixos-unstable-small edk2-pytool-library-0.22.3
pkgs.python312Packages.edk2-pytool-library
Python library package that supports UEFI development
-
nixos-unstable edk2-pytool-library-0.22.3
- nixpkgs-unstable edk2-pytool-library-0.22.3
- nixos-unstable-small edk2-pytool-library-0.22.3
Package maintainers
-
@mjoerg Martin Joerg <martin.joerg@gmail.com>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@NickCao Nick Cao <nickcao@nichi.co>