← Back

CVE-2015-5281

nvd nist
Published: Nov 24, 2015Modified: May 6, 2026

JSON object

Loading...
2.6
Vector
AV:L/AC:H/Au:N/C:P/I:P/A:N
Exploitability: 1.9 / Impact: 4.9
Source: NVD

Description

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

Affected (1)

1 product
Enterprise Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0

Related CWEs

Timeline

No history available yet.