EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade edk2-aarch64Upgrade edk2-debuginfoUpgrade edk2-ovmfUpgrade edk2-toolsUpgrade edk2-tools-doc | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade edk2 | Jul 23, 2026 | Jul 23, 2026 |
| Ubuntu | — | Upgrade ovmf-ia32Upgrade qemu-efi-armUpgrade ovmfUpgrade qemu-efi-riscv64Upgrade qemu-efi-loongarch64Upgrade qemu-efi-aarch64Upgrade qemu-efi | Oct 30, 2025 | Aug 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub