We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-49721



Description

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Reserved 2023-12-05 | Published 2024-02-14 | Updated 2024-10-24 | Assigner canonical


MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Any version
affected

Credits

Mate Kukri finder

References

bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 issue-tracking

nvd.nist.gov/vuln/detail/CVE-2023-48733 issue-tracking

www.openwall.com/lists/oss-security/2024/02/14/4 mailing-list

bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 issue-tracking

cve.org (CVE-2023-49721)

nvd.nist.gov (CVE-2023-49721)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-49721

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.