NA

CVE-2023-4692

Published: 25/10/2023 Updated: 30/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an malicious user to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu grub2

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

Maxim Suhanov discovered multiple vulnerabilities in GURB2's code to handle NTFS filesystems, which may result in a Secure Boot bypass For the oldstable distribution (bullseye), these problems have been fixed in version 206-3~deb11u6 For the stable distribution (bookworm), these problems have been fixed in version 206-13+deb12u1 We recommend t ...
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption In some circumstances, the attack may also corrupt the UEFI firmware heap metadata As a result, arbitrary code execution and secure boot protecti ...
Description<!---->An out-of-bounds write flaw was found in grub2's NTFS filesystem driver This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption In some circumstances, the attack may also corrupt the UEFI firmware heap metadata As a result, arbitrary code execution and se ...