2.6
CVSSv2

CVE-2015-5281

Published: 24/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 2.6 | Impact Score: 4.9 | Exploitability Score: 1.9
VMScore: 231
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

The grub2 package prior to 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate malicious users to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 7.0

Vendor Advisories

Synopsis Low: grub2 security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic Updated grub2 packages that fix one security issue, several bugs, and addone enhancement are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having Low secu ...
It was discovered that grub2 builds for EFI systems contained modules that were not suitable to be loaded in a Secure Boot environment An attacker could use this flaw to circumvent the Secure Boot mechanisms and load non-verified code Attacks could use the boot menu if no password was set, or the grub2 configuration file if the attacker has root ...