ZeroHour

CVE-2020-15706

CVSS 3.1
6.4 medium
EPSS
<1%p60
Published
()
Modified
Description

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

Vendors
gnuredhatcanonicaldebiansusemicrosoftopensuse
Products
grub2, enterprise linux atomic host, openshift container platform, ubuntu linux, debian linux, enterprise linux, suse linux enterprise server, windows 10, windows 8.1, windows rt 8.1, windows server 2012, windows server 2016
Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.