CVE-2023-49721

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/02/2024
Last modified:
26/08/2025

Description

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* 5.0.0 (including) 5.21.0 (excluding)
cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:* 2023.11-8 (including)