VDB
BDU%3A2022-05896
BDU%3A2022-05896
PUBLISHED
CVSS 6 MEDIUM
Уязвимость реализации механизма верификации shim_lock загрузчика операционных систем Grub2, позволяющая нарушителю выполнить произвольный код и получить полный контроль над устройством
Risk Scores
CVSS 2.0
6
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Erich Boleyn, ООО «Ред Софт», ФССП России | Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows 10, Windows 10 1607, Windows Server 2016, Windows RT 8.1, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Grub2, Windows 10 20H2, Windows Server 20H2 (Server Core Installation), Windows 10 21H1, Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11, РЕД ОС (запись в едином реестре российских программ №3751), ОС ТД АИС ФССП России, Windows Server 2012 (Server Core installation) |
Timeline
- Sep 23, 2022 CVE Published
- Sep 28, 2022 CVE Updated
- Mar 19, 2026 Security Advisory
References
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-grub-/?sphrase_id=63279 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-3418 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1933757 url
- https://git.savannah.gnu.org/gitweb/?p=grub.git&view=view+git+repository advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://msrc.microsoft.com/update-guide/vulnerability/ADV200011 advisory
- https://goslinux.fssp.gov.ru/2726972/ advisory