CVE-2023-48733: Medium severity debian/edk2 vulnerability
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48733?
CVE-2023-48733 is considered a high severity vulnerability as it allows an OS-resident attacker to bypass Secure Boot.
How do I fix CVE-2023-48733?
To fix CVE-2023-48733, upgrade your edk2 package to the remedied versions specified for your distribution.
Which versions of edk2 are affected by CVE-2023-48733?
CVE-2023-48733 affects specific versions of the edk2 package in Debian and Ubuntu, including versions up to 2020.11-2+deb11u1 for Debian and 0~20191122 for Ubuntu Focal.
What systems are impacted by CVE-2023-48733?
CVE-2023-48733 impacts systems running vulnerable versions of the edk2 package in Ubuntu and Debian distributions.
Is there a workaround for CVE-2023-48733?
Currently, there are no effective workarounds for CVE-2023-48733 other than upgrading to the secure versions of the edk2 package.