V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-0624
AST
High

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user …

CVSS
7.6
High
EPSS
0.01
p68
Published
2025-01-01
Updated
2025-01-01
Description

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails to consider the environment variable length when allocating the internal buffer, resulting in an out-of-bounds write. If correctly exploited, this issue may result in remote code execution through the same network segment grub is searching for the boot information, which can be used to by-pass secure boot protections.

Tags · CWE
CWE-787
Affected products
Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2-signedGrub2-signedGrub2-signedGrub2-unsignedGrub2-unsignedGrub2-unsigned
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: A
Adjacent Network (A)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.014 · p68
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2-signedTracked
grub2-signedTracked
grub2-signedTracked
grub2-unsignedTracked
grub2-unsignedTracked
grub2-unsignedTracked
Source databases
AST
DEB
UBU
Related vulnerabilities