An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
2024-02-14T22:15:47.320
2025-08-26T17:19:40.457
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | canonical | lxd | 5.0 | Yes |
| Application | canonical | lxd | 5.21 | Yes |
| Application | canonical | lxd | 5.21 | Yes |
| Application | tianocore | edk2 | ≤ 2023.11-8 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |