EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.
CVSS Details
- CVSS 4.0 Base Score: 8.4 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade edk2-debuginfoUpgrade edk2-tools-docUpgrade edk2-ovmfUpgrade edk2-aarch64Upgrade edk2-tools | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade edk2 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | Upgrade edk2-ovmfUpgrade edk2-toolsUpgrade edk2-tools-docUpgrade edk2-debugsourceUpgrade edk2-tools-debuginfoNo solution existsUpgrade edk2-aarch64 | May 20, 2026 | Dec 9, 2025 |
| Rocky_linux | — | Upgrade edk2-debugsourceUpgrade edk2-toolsUpgrade edk2-tools-debuginfo | Jun 1, 2026 | May 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub