CVE-2023-48733
published 2024-02-14CVE-2023-48733: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.26%
17.0th percentile
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxd | — | — |
| canonical | lxd | — | — |
| debian | debian_linux | — | — |
| debian | edk2 | < edk2 2022.11-6+deb12u1 (bookworm) | edk2 2022.11-6+deb12u1 (bookworm) |
| tianocore | edk2 | <= 2023.11-8 | — |
| tianocore | edk2 | — | — |
| tianocore | edk2 | — | — |
| tianocore | edk2 | >= 0 < 2020.11-2+deb11u2 | 2020.11-2+deb11u2 |
| tianocore | edk2 | >= 0 < 2022.11-6+deb12u1 | 2022.11-6+deb12u1 |
| tianocore | edk2 | >= 0 < 2023.11-7 | 2023.11-7 |
| tianocore | edk2 | >= 0 < 2023.11-7 | 2023.11-7 |
| tianocore | edk2 | >= 0 < 0~20191122.bd85bf54-2ubuntu3.5 | 0~20191122.bd85bf54-2ubuntu3.5 |
| tianocore | edk2 | >= 0 < 2022.02-3ubuntu0.22.04.2 | 2022.02-3ubuntu0.22.04.2 |
| ubuntu | edk2 | >= 2024.02 < 2024.02-2ubuntu0.3 | 2024.02-2ubuntu0.3 |
| ubuntu | edk2 | >= 2024.05 < 2024.05-2ubuntu0.3 | 2024.05-2ubuntu0.3 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-2486: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
osv·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CVE-2025-2486: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
GHSA
GHSA-g658-h443-xpr6: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
ghsa_unreviewed·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CWE-489 GHSA-g658-h443-xpr6: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
GHSA
GHSA-cjc8-gmgf-qv2g: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2
ghsa_unreviewed·2024-02-15
CVE-2023-48733 [MEDIUM] CWE-1188 GHSA-cjc8-gmgf-qv2g: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
OSV
edk2 vulnerabilities
osv·2024-02-15·CVSS 7.8
CVE-2022-36763 [HIGH] edk2 vulnerabilities
edk2 vulnerabilities
Marc Beatove discovered buffer overflows exit in EDK2. An attacker on the
local network could potentially use this to impact availability or possibly
cause remote code execution. (CVE-2022-36763, CVE-2022-36764,
CVE-2022-36765)
It was discovered that a buffer overflows exists in EDK2's Network Package
An attacker on the local network could potentially use these to impact
availability or possibly cause remote code execution. (CVE-2023-45230,
CVE-2023-45234, CVE-2023-45235)
It was discovered that an out-of-bounds read exists in EDK2's Network
Package An attacker on the local network could potentially use this to
impact confidentiality. (CVE-2023-45231)
It was discovered that infinite-loops exists in EDK2's Network Package
An attacker on the local network could potent
OSV
CVE-2023-48733: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2
osv·2024-02-14·CVSS 6.7
CVE-2023-48733 [MEDIUM] CVE-2023-48733: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Red Hat
edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
vendor_redhat·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CWE-489 edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
A flaw was found in edk2. This vulnerability allows bypass of Secure Boot (Unified Extensible Firmware Interface) constraints via accidentally allowing the UEFI Shell to be accessed in Secure Boot envi
Debian
CVE-2025-2486: edk2 - The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be...
vendor_debian·2025·CVSS 6.7
CVE-2025-2486 [MEDIUM] CVE-2025-2486: edk2 - The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be...
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
Scope: local
bookworm: resolved (fixed in 2022.11-6+deb12u1)
bullseye: resolved (fixed in 2020.11-2+deb11u2)
forky: resolved (fixed in 2023.11-7)
sid: resolved (fixed in 2023.11-7)
trixie: resolved (fixed in 2023.11-7)
Ubuntu
EDK II vulnerabilities
vendor_ubuntu·2024-02-15·CVSS 7.0
CVE-2023-45232 [HIGH] EDK II vulnerabilities
Title: EDK II vulnerabilities
Summary: Several security issues were fixed in EDK II.
Marc Beatove discovered buffer overflows exit in EDK2. An attacker on the
local network could potentially use this to impact availability or possibly
cause remote code execution. (CVE-2022-36763, CVE-2022-36764,
CVE-2022-36765)
It was discovered that a buffer overflows exists in EDK2's Network Package
An attacker on the local network could potentially use these to impact
availability or possibly cause remote code execution. (CVE-2023-45230,
CVE-2023-45234, CVE-2023-45235)
It was discovered that an out-of-bounds read exists in EDK2's Network
Package An attacker on the local network could potentially use this to
impact confidentiality. (CVE-2023-45231)
It was discovered that infinite-loops exists in EDK
Debian
CVE-2023-48733: edk2 - An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK...
vendor_debian·2023·CVSS 6.7
CVE-2023-48733 [MEDIUM] CVE-2023-48733: edk2 - An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK...
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Scope: local
bookworm: resolved (fixed in 2022.11-6+deb12u1)
bullseye: resolved (fixed in 2020.11-2+deb11u2)
forky: resolved (fixed in 2023.11-7)
sid: resolved (fixed in 2023.11-7)
trixie: resolved (fixed in 2023.11-7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139https://lists.debian.org/debian-lts-announce/2024/06/msg00028.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2023-48733https://www.openwall.com/lists/oss-security/2024/02/14/4https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139https://lists.debian.org/debian-lts-announce/2024/06/msg00028.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2023-48733https://www.openwall.com/lists/oss-security/2024/02/14/4
2024-02-14
Published