https://seclists.org/oss-sec/2024/q1/136: Secure Boot bypass in EDK2 based Virtual Machine firmware
Published Feb 14, 2024
·Updated
Affected Software
3 affected components
Ubuntu edk2
OVMF OVMF
AAVMF AAVMF
Frequently Asked Questions
1
What is the severity of CVE-2024-XXXX?
The severity of CVE-2024-XXXX is critical due to its potential to bypass Secure Boot mechanisms.
2
How do I fix CVE-2024-XXXX?
To fix CVE-2024-XXXX, update your EDK2 firmware to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-XXXX?
CVE-2024-XXXX affects systems utilizing EDK2 firmware including Ubuntu, OVMF, and AAVMF.
4
What is the impact of CVE-2024-XXXX?
The impact of CVE-2024-XXXX allows an attacker to run arbitrary code with elevated permissions by bypassing Secure Boot.
5
Is there a workaround for CVE-2024-XXXX?
Currently, the recommended workaround for CVE-2024-XXXX is to disable the use of built-in applications in the firmware until a patch is applied.