tianocore EDK2
cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*, +1 more
- <= 202502
A vulnerability in the EDK2 OVMF package prior to version 202502 allows for a bypass of the Secure Boot mechanism in direct boot mode. When Secure Boot is enabled, the DxeImageVerification process verifies the signature of the Linux kernel before it is loaded. However, if the signature is not recognized, DxeImageVerification denies access and the system falls back to a legacy loader, bypassing Secure Boot. This vulnerability could be exploited to alter control flow, potentially leading to arbitrary command execution.
Exploitation of this vulnerability could bypass Secure Boot, allowing unauthorized code to be executed with elevated privileges.
Users can upgrade to EDK2 OVMF version 202505 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.