The GRUB boot manager is more an operating system than a boot loader. For example, it has more than 20 file system types supported!
This is a really wide attack surface… And, currently, GRUB is the default choice in the Secure Boot implementation using Microsoft-signed shims (but things are moving forward).
Some time ago, I discovered two vulnerabilities (or three vulnerabilities, if we count a security issue which is almost unexploitable) in the NTFS driver of the GRUB boot manager. And here are some technical details…
Continue reading “CVE-2023-4692, CVE-2023-4693: vulnerabilities in the GRUB boot manager”