cvedb.io
CVE-2023-4692
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2023-10-25T18:17:41.743 · Last modified 2026-07-21T06:16:27.400

Summary

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.

Affected products

gnu — grub2

Does this affect you?

Add your gear to cvedb and we'll alert you only when gnu ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.