#VU51189 Out-of-bounds write in grub - CVE-2020-25647
Published: March 3, 2021 / Updated: December 17, 2024
grub
GNU
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing untrusted input from USB device in grub_usb_device_initialize(). An attacker with physical access to the system can trigger an out-of-bounds write error with a malicious USB drive, bypass Secure Boot protection and execute arbitrary code on the system with elevated privileges.