Critical vulnerability affecting most Linux distros allows for bootkits

๐“ข๐“ฎ๐“ฎ๐“™๐“ช๐”‚๐“”๐“ถ๐“ถ@lemmy.procrastinati.org to Linux@lemmy.ml – 145 points –
Critical vulnerability affecting most Linux distros allows for bootkits
arstechnica.com
26

You are viewing a single comment

I wonder if Matt calculated CVSS score before calling this vulnerability "critical".

Itโ€™s the last sentence of the article - 9.8/10. In this case itโ€™s probably called critical because of the potential consequences of the exploit being a full machine takeover, not the likeliness of the exploit being used.

It means that CVSS is calculated wrong. It can't be so big because default configuration is not affected and attacker requires admin access to change it.