CVE Published: 25/10/2023 |
CVE Updated: 23/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: |
Product: Status : PUBLISHED
CVE-2023-4692 Description
An out-of-bounds write flaw was found in grub2\'s NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub\'s heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.