📦 Edk2

by Tianocore

🔍 What is Edk2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2486

HIGH CVSS 8.8 Nov 26, 2025

This CVE allows attackers to bypass Secure Boot restrictions by accessing the UEFI Shell in Ubuntu systems with vulnerable edk2 firmware. This could enable booting unauthorized operating systems or lo...

CVE-2023-45232

HIGH CVSS 7.5 Jan 16, 2024

CVE-2023-45232 is an infinite loop vulnerability in EDK2's Network Package when parsing unknown IPv6 Destination Options headers. This allows attackers to cause denial of service by sending specially ...

CVE-2023-45234

HIGH CVSS 8.3 Jan 16, 2024

A buffer overflow vulnerability in EDK2's Network Package allows attackers to execute arbitrary code by sending malicious DHCPv6 Advertise messages. This affects systems using EDK2-based firmware with...

CVE-2023-45230

HIGH CVSS 8.3 Jan 16, 2024

EDK2's Network Package has a buffer overflow vulnerability in the DHCPv6 client when processing long server ID options. Attackers on the same network can exploit this to execute arbitrary code or caus...

CVE-2022-36764

HIGH CVSS 7.0 Jan 9, 2024

CVE-2022-36764 is a heap buffer overflow vulnerability in EDK2's Tcg2MeasurePeImage() function that allows local network attackers to potentially execute arbitrary code or cause denial of service. Thi...

CVE-2021-38578

HIGH CVSS 7.4 Mar 3, 2022

CVE-2021-38578 is a buffer underflow vulnerability in Tianocore EDK II's System Management Mode (SMM) entry point that allows attackers to corrupt SMRAM memory. This affects systems using vulnerable U...

CVE-2021-38576

HIGH CVSS 7.5 Jan 3, 2022

A BIOS firmware vulnerability in certain PC models leaves the Platform authorization value empty, allowing attackers to permanently brick the TPM chip or cause temporary denial-of-service. This affect...

CVE-2021-28213

HIGH CVSS 7.5 Jun 11, 2021

CVE-2021-28213 involves a security risk in EDK2's IpSecDxe.efi where an example encrypted private key is present, potentially allowing attackers to decrypt network traffic or impersonate systems. This...

CVE-2019-14584

HIGH CVSS 7.8 Jun 3, 2021

CVE-2019-14584 is a null pointer dereference vulnerability in Tianocore EDK2 firmware that allows an authenticated local user to potentially escalate privileges. This affects systems using vulnerable ...