CVE-2023-4692

CVSS V2 None CVSS V3 None
Description
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
Overview
  • CVE ID
  • CVE-2023-4692
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-25T10:27:29.173Z
  • Last Modified Date
  • 2024-05-29T22:14:59.233Z
History
Created Old Value New Value Data Type Notes
2024-06-24 19:49:16 Added to TrackCVE