GCP-2024-001
<strong>Published:</strong><br/><table class="fixed"> <thead> <tr> <th width="70%">Description</th> <th>Severity</th> <th>Notes</th> </tr> </thead> <tbody> <tr> <td> <p>Several vulnerabilities were discovered in the TianoCore EDK II UEFI firmware. This firmware is used in Google Compute Engine VMs. If exploited, the vulnerabilities could allow a bypass of secure boot, which would provide false measurements in the secure boot process, including when used in Shielded VMs.</p> <h4 data-text="What should I do?" id="what-should-i-do_15" tabindex="-1">What should I do?</h4> <p>No action is required. Google has patched this vulnerability across Compute Engine and all VMs are protected from this vulnerability.</p> <h4 data-text="What vulnerabilities are addressed by this patch?" id="what-vulnerabilities-are-addressed-by-this-patch" tabindex="-1">What vulnerabilities are addressed by this patch?</h4> <p>The patch mitigated the following vulnerabilities:</p> <ul> <li>CVE-2022-36763</li> <li>CVE-2022-36764</li> <li>CVE-2022-36765</li> </ul> </td> <td> Medium </td> <td> <ul> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-36763" target="mitre">CVE-2022-36763</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-36764" target="mitre">CVE-2022-36764</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-36765" target="mitre">CVE-2022-36765</a></li> </ul> </td> </tr> </tbody> </table>
Timeline
- Apr 14, 2026 CVE Published