Edk2 · Edk2 · CVE-2023-48733
**Name of the Vulnerable Software and Affected Versions**
EDK2 versions (affected versions not specified)
**Description**
The issue is related to an insecure default configuration in EDK2 that allows the UEFI Shell to be enabled, potentially permitting an OS-resident attacker to bypass Secure Boot. This could lead to unauthorized access to confidential data, disruption of data integrity, and denial of service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.