CVE-2023-48733

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Configurations

No configuration.

History

08 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-1188

21 Nov 2024, 08:32

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 -
References () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 -
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html -
References () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 -
References () https://www.openwall.com/lists/oss-security/2024/02/14/4 - () https://www.openwall.com/lists/oss-security/2024/02/14/4 -

30 Jun 2024, 23:15

Type Values Removed Values Added
Summary
  • (es) Un valor predeterminado inseguro para permitir UEFI Shell en EDK2 se dejó habilitado en EDK2 de Ubuntu. Esto permite que un atacante residente en el sistema operativo omita el arranque seguro.
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html -

14 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 22:15

Updated : 2025-05-08 16:15


NVD link : CVE-2023-48733

Mitre link : CVE-2023-48733

CVE.ORG link : CVE-2023-48733


JSON object : View

Products Affected

No product.

CWE
CWE-1188

Initialization of a Resource with an Insecure Default