CVE-2025-2486
published 2025-11-26CVE-2025-2486: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot…
PriorityP347high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.12%
1.9th percentile
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2022.11-6+deb12u1 (bookworm) | edk2 2022.11-6+deb12u1 (bookworm) |
| msrc | azl3_edk2_20240524git3e722403cd16-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240524git3e722403cd16-11_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-23_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-25_on_azure_linux_3.0 | — | — |
| msrc | cbl2_edk2_20230301gitf80f052277c8-43_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_edk2_20230301gitf80f052277c8-44_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hvloader_1.0.1-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hvloader_1.0.1-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qemu_6.2.0-25_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qemu_6.2.0-26_on_cbl_mariner_2.0 | — | — |
| tianocore | edk2 | — | — |
| tianocore | edk2 | — | — |
| tianocore | edk2 | >= 0 < 2020.11-2+deb11u2 | 2020.11-2+deb11u2 |
| tianocore | edk2 | >= 0 < 2022.11-6+deb12u1 | 2022.11-6+deb12u1 |
| tianocore | edk2 | >= 0 < 2023.11-7 | 2023.11-7 |
| tianocore | edk2 | >= 0 < 2023.11-7 | 2023.11-7 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.03.7LOWCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.7MEDIUM
vendor_msrc8.8HIGH
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
vendor_redhat·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CWE-489 edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
A flaw was found in edk2. This vulnerability allows bypass of Secure Boot (Unified Extensible Firmware Interface) constraints via accidentally allowing the UEFI Shell to be accessed in Secure Boot envi
Microsoft
UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
vendor_msrc·2025-11-11·CVSS 8.8
CVE-2025-2486 [LOW] CWE-489 UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Debian
CVE-2025-2486: edk2 - The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be...
vendor_debian·2025·CVSS 6.7
CVE-2025-2486 [MEDIUM] CVE-2025-2486: edk2 - The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be...
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
Scope: local
bookworm: resolved (fixed in 2022.11-6+deb12u1)
bullseye: resolved (fixed in 2020.11-2+deb11u2)
forky: resolved (fixed in 2023.11-7)
sid: resolved (fixed in 2023.11-7)
trixie: resolved (fixed in 2023.11-7)
OSV
CVE-2025-2486: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
osv·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CVE-2025-2486: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
GHSA
GHSA-g658-h443-xpr6: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
ghsa_unreviewed·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CWE-489 GHSA-g658-h443-xpr6: The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Sec
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-26
Published