VDB
BDU%3A2022-05895
BDU%3A2022-05895
PUBLISHED
CVSS 6 MEDIUM
Уязвимость реализации протокола безопасной загрузки Secure Boot загрузчика операционных систем Grub2, позволяющая нарушителю выполнить произвольный код и получить полный контроль над устройством
Risk Scores
CVSS 2.0
6
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Red Hat Inc., Canonical Ltd., Novell Inc., Сообщество свободного программного обеспечения, Erich Boleyn, ООО «Ред Софт», ФССП России | Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows 10, Windows 10 1607, Red Hat Enterprise Linux, Windows Server 2016, Windows RT 8.1, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Ubuntu, Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), OpenSUSE Leap, Debian GNU/Linux, Grub2, Windows 10 20H2, Windows Server 20H2 (Server Core Installation), Windows 10 21H1, Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11, РЕД ОС (запись в едином реестре российских программ №3751), ОС ТД АИС ФССП России, Windows Server 2012 (Server Core installation) |
Timeline
- Sep 23, 2022 CVE Published
- Sep 28, 2022 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- https://security.gentoo.org/glsa/202104-05 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-grub-/?sphrase_id=63279 url
- https://git.savannah.gnu.org/gitweb/?p=grub.git&view=view+git+repository url
- https://access.redhat.com/security/cve/cve-2020-15705 url
- https://ubuntu.com/security/notices/USN-4432-1 url
- http://www.openwall.com/lists/oss-security/2020/07/29/3 url
- http://www.openwall.com/lists/oss-security/2021/03/02/3 url
- http://www.openwall.com/lists/oss-security/2021/09/17/2 url
- http://www.openwall.com/lists/oss-security/2021/09/17/4 url
- http://www.openwall.com/lists/oss-security/2021/09/21/1 url
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass url
- https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15705 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/VHOMHHK6YNMLF2MBP6E2P2NPYVKF47G6/ advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/UGKES3MGRD44EG6DD3EOHLZZXMVRVSC3/ advisory
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV200011 advisory
- https://goslinux.fssp.gov.ru/2726972/ advisory