CVE-2025-2486: UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploit Status
Not Exploited
Patch Tuesday
2025-Nov
Released
2025-11-29
Last Updated
2026-01-13
EPSS Score
0.03% (percentile: 6.8%)

Affected Products (10)

Other

  • 20377-17086
  • 20577-17084
  • 20378-17086
  • 20691-17086
  • 20727-17084
  • 20779-17086
  • 20780-17086
  • 20602-17086
  • 20615-17084
  • 20793-17084

Revision History

  • 2025-11-29: Information published.
  • 2025-12-06: Information published.
  • 2025-12-07: Information published.
  • 2025-12-11: Information published.
  • 2025-12-16: Information published.
  • 2026-01-03: Information published.
  • 2026-01-08: Information published.
  • 2026-01-13: Information published.