CVE-2023-49721Incorrect Default Permissions in Edk2

Severity
6.7MEDIUMNVD
EPSS
0.0%
top 96.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateFeb 15

Description

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages3 packages

NVDtianocore/edk22023.11-8
NVDcanonical/lxd5.0.05.21.0
CVEListV5canonical_ltd/lxd0

🔴Vulnerability Details

2
GHSA
GHSA-4639-7gfm-29p2: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD2024-02-15
CVEList
CVE-2023-49721: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD2024-02-14

📋Vendor Advisories

1
Debian
CVE-2023-49721: incus - An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This al...2023
CVE-2023-49721 — Incorrect Default Permissions in Edk2 | cvebase