Ubuntu edk2
cpe:2.3:a:tianocore:edk2:*:*:*:*:*:*:*, +1 more
- >= 2024.05-2ubuntu0.0, < 2024.05-2ubuntu0.3
- >= 2024.02-2ubuntu0.0, < 2024.02-2ubuntu0.3
A vulnerability in the Ubuntu edk2 UEFI firmware packages allows access to the UEFI Shell in Secure Boot environments, potentially bypassing Secure Boot restrictions. This issue affects the AAVMF Secure Boot images in Ubuntu Noble and Oracular, which still allow launching the Shell with Secure Boot enabled. In response to a related vulnerability, CVE-2023-48733, the UEFI Shell was disabled in Secure Boot OVMF images, but this fix was not properly applied to AAVMF.
Exposing the UEFI Shell in Secure Boot mode can lead to a security bypass, allowing actions that would normally be restricted under Secure Boot.
Users can upgrade to edk2 version 2024.05-2ubuntu0.3 or 2024.02-2ubuntu0.3, both of which disable the UEFI Shell in Secure Boot environments.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.