Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-4692

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.2%
CVSS Severity
CVSS v3 Score 7.5
References
Products affected by CVE-2023-4692
  • Gnu » Grub2 » Version: N/A
    cpe:2.3:a:gnu:grub2:-
  • Gnu » Grub2 » Version: 1.98
    cpe:2.3:a:gnu:grub2:1.98
  • Gnu » Grub2 » Version: 1.99
    cpe:2.3:a:gnu:grub2:1.99
  • Gnu » Grub2 » Version: 2.00
    cpe:2.3:a:gnu:grub2:2.00
  • Gnu » Grub2 » Version: 2.01
    cpe:2.3:a:gnu:grub2:2.01
  • Gnu » Grub2 » Version: 2.02
    cpe:2.3:a:gnu:grub2:2.02
  • Gnu » Grub2 » Version: 2.04
    cpe:2.3:a:gnu:grub2:2.04
  • Gnu » Grub2 » Version: 2.06
    cpe:2.3:a:gnu:grub2:2.06
  • Gnu » Grub2 » Version: 2.06-150400.7.1
    cpe:2.3:a:gnu:grub2:2.06-150400.7.1
  • Gnu » Grub2 » Version: 2.06-18.1
    cpe:2.3:a:gnu:grub2:2.06-18.1
  • Redhat » Enterprise Linux » Version: 8.0
    cpe:2.3:o:redhat:enterprise_linux:8.0
  • Redhat » Enterprise Linux » Version: 9.0
    cpe:2.3:o:redhat:enterprise_linux:9.0


Contact Us

Shodan ® - All rights reserved