CVE-2023-49721

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Configurations

No configuration.

History

21 Nov 2024, 08:33

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 -
References () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 -
References () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 -
References () https://www.openwall.com/lists/oss-security/2024/02/14/4 - () https://www.openwall.com/lists/oss-security/2024/02/14/4 -

24 Oct 2024, 17:35

Type Values Removed Values Added
CWE CWE-276
Summary
  • (es) Un valor predeterminado inseguro para permitir UEFI Shell en EDK2 se dejó habilitado en LXD. Esto permite que un atacante residente en el sistema operativo omita el arranque seguro.

14 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 22:15

Updated : 2024-11-21 08:33


NVD link : CVE-2023-49721

Mitre link : CVE-2023-49721

CVE.ORG link : CVE-2023-49721


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions