Remote Code Execution Vulnerability in Shim Boot Support

CVE-2023-40547
8.3HIGH

Key Information

Vendor
Red Hat
Status
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.2 Advanced Update Support
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
Vendor
CVE Published:
25 January 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

CVE-2023-40547 is a critical vulnerability that was found in Shim, a software component essential for secure boot functionality in various Linux distributions. This flaw allows for remote code execution and complete system compromise by crafting a specific malicious HTTP request. The vulnerability is only exploitable during the early boot phase and impacts Linux distributions like Ubuntu, Debian, and Oracle Linux. A patch has been released to address this issue, and it is essential for Linux users to update their systems promptly to secure their boot process.

Affected Version(s)

Red Hat Enterprise Linux 7 <= 0:15.8-3.el7

Red Hat Enterprise Linux 7 <= 0:15.8-1.el7

Red Hat Enterprise Linux 8 <= 0:15.8-4.el8_9

News Articles

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • First article discovered by Penetration Testing

  • Vulnerability published.

  • Vulnerability Reserved.

  • Reported to Red Hat.

Collectors

NVD DatabaseMitre DatabaseRed Hat Feed20 News Article(s)

Credit

Red Hat would like to thank Bill Demirkapi (Microsoft Security Response Center) for reporting this issue.
.