Vulnerability · NVD
CVE-2022-2601
CVE-2022-2601 : high severity (CVSS 8.6). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 8.6
- Exploitation
- 0.5 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.
Show raw CVSS vector
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2022 (Server Core installation) Fixed in 10.0.20348.3453
- Windows Server 2022 Fixed in 10.0.25398.1551
- Windows Server 2019 Fixed in 10.0.17763.7136
- Windows Server 2016 Fixed in 10.0.14393.7969
- Windows 11 24H2 · 2024-H2 Fixed in 10.0.26100.3775
- Windows 11 23H2 · 2023-H2 Fixed in 10.0.22631.5189
- Windows 11 22H2 · 2022-H2 Fixed in 10.0.22621.5189
- Windows 11 21H2 · 2021-H2 Fixed in 10.0.22000.3147
- Windows 10 22H2 · 2022-H2 Fixed in 10.0.19045.5737
- Windows 10 21H2 · 2021-H2 Fixed in 10.0.19044.5737
- Windows 10 1809 · 2018-09 Fixed in 10.0.17763.7136
- Windows 10 1607 · 2016-07 Fixed in 10.0.14393.7969
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.