Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4692

Опубликовано: 03 окт. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

Отчет

This vulnerability is considered as 'Low' severity by Red Hat as the NTFS module is not shipped as part of Red Hat's signed grub2 image.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7grub2Out of support scope
Red Hat Enterprise Linux 8grub2FixedRHSA-2024:318422.05.2024
Red Hat Enterprise Linux 9grub2FixedRHSA-2024:245630.04.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2236613grub2: Out-of-bounds write at fs/ntfs.c may lead to unsigned code execution

EPSS

Процентиль: 0%
0.00004
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

CVSS3: 7.5
nvd
больше 1 года назад

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 1 года назад

An out-of-bounds write flaw was found in grub2's NTFS filesystem drive ...

CVSS3: 5.3
github
больше 1 года назад

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

EPSS

Процентиль: 0%
0.00004
Низкий

7.5 High

CVSS3