An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
2024-02-14T22:15:47.320
2025-08-26T17:19:40.457
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | canonical | lxd | 5.0 | Yes |
Application | canonical | lxd | 5.21 | Yes |
Application | canonical | lxd | 5.21 | Yes |
Application | tianocore | edk2 | ≤ 2023.11-8 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |