CVE-2023-49721

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*

History

26 Aug 2025, 17:19

Type Values Removed Values Added
CPE cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
References () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - Issue Tracking
References () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - Issue Tracking
References () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - Third Party Advisory
References () https://www.openwall.com/lists/oss-security/2024/02/14/4 - () https://www.openwall.com/lists/oss-security/2024/02/14/4 - Mailing List
First Time Canonical lxd
Canonical
Tianocore edk2
Tianocore

21 Nov 2024, 08:33

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 -
References () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 -
References () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 -
References () https://www.openwall.com/lists/oss-security/2024/02/14/4 - () https://www.openwall.com/lists/oss-security/2024/02/14/4 -

24 Oct 2024, 17:35

Type Values Removed Values Added
CWE CWE-276
Summary
  • (es) Un valor predeterminado inseguro para permitir UEFI Shell en EDK2 se dejó habilitado en LXD. Esto permite que un atacante residente en el sistema operativo omita el arranque seguro.

14 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 22:15

Updated : 2025-08-26 17:19


NVD link : CVE-2023-49721

Mitre link : CVE-2023-49721

CVE.ORG link : CVE-2023-49721


JSON object : View

Products Affected

canonical

  • lxd

tianocore

  • edk2
CWE
CWE-276

Incorrect Default Permissions