A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2023-4692

CVE-2023-4692: GNU GRUB2 RCE Vulnerability

CVE-2023-4692 is an out-of-bounds write RCE flaw in GNU GRUB2's NTFS driver that enables heap corruption and secure boot bypass. This article covers technical details, affected versions, impact, and mitigation.

Updated: May 15, 2026

CVE-2023-4692 Overview

CVE-2023-4692 is an out-of-bounds write vulnerability in the New Technology File System (NTFS) driver of GNU GRUB2, the bootloader used by most Linux distributions. An attacker who can present a specially crafted NTFS filesystem image to GRUB2 can corrupt the bootloader's heap metadata. Under specific conditions, the corruption extends to the Unified Extensible Firmware Interface (UEFI) firmware heap. This allows arbitrary code execution at the firmware level and bypass of Secure Boot protections. The flaw is tracked under [CWE-122] (heap-based buffer overflow) and [CWE-787] (out-of-bounds write). Red Hat Enterprise Linux 8 and 9, along with upstream GNU GRUB2, are affected.

Critical Impact

Successful exploitation enables arbitrary code execution in the pre-boot environment and bypass of UEFI Secure Boot, undermining the root of trust for the entire operating system.

Affected Products

  • GNU GRUB2 (upstream, all versions prior to patched release)
  • Red Hat Enterprise Linux 8.0
  • Red Hat Enterprise Linux 9.0

Discovery Timeline

  • 2023-10-25 - CVE-2023-4692 published to the National Vulnerability Database (NVD)
  • 2025-11-04 - Last updated in NVD database

Technical Details for CVE-2023-4692

Vulnerability Analysis

The defect resides in GRUB2's NTFS filesystem driver, which parses filesystem metadata during boot. When the driver processes a malformed NTFS image, it writes data beyond an allocated heap buffer. This corrupts GRUB2's internal heap structures and, depending on memory layout, can spill into the UEFI firmware's heap.

Because GRUB2 executes before the operating system kernel and before Secure Boot hands control to the kernel, code injected through this path runs with firmware-level privileges. An attacker can therefore install a bootkit that survives operating system reinstallation. Exploitation requires local access and low privileges, since the attacker must either modify a mounted disk or attach a removable device containing the crafted NTFS image.

Root Cause

The root cause is insufficient bounds validation in the NTFS driver when parsing attributes within Master File Table (MFT) entries. The driver trusts length fields supplied by the filesystem image and writes parsed data into a fixed-size heap allocation. A crafted image with oversized or malformed attributes produces a heap-based out-of-bounds write.

Attack Vector

A local attacker stages a malicious NTFS image on storage that GRUB2 will read during boot. This includes USB flash drives, secondary partitions, or virtual disks attached to a workstation or server. When GRUB2 mounts the NTFS volume to load configuration files, kernels, or initramfs images, the vulnerable parser is invoked and heap corruption occurs.

// No verified exploit code is publicly available.
// The vulnerability is triggered by parsing a crafted NTFS
// filesystem image. See the Red Hat advisory for technical
// details: https://access.redhat.com/security/cve/CVE-2023-4692

Detection Methods for CVE-2023-4692

Indicators of Compromise

  • Unexpected NTFS partitions or images present on Linux systems that do not legitimately use NTFS volumes.
  • Modifications to the EFI System Partition (ESP), including unsigned or unknown .efi binaries.
  • GRUB2 boot failures, panics, or unexplained reboots during the early boot phase.
  • Changes to UEFI firmware variables or Secure Boot configuration without corresponding administrative action.

Detection Strategies

  • Audit installed grub2 package versions against vendor advisories such as RHSA-2024:2456 and RHSA-2024:3184.
  • Validate measured boot logs and Trusted Platform Module (TPM) PCR values to detect deviations in the boot chain.
  • Use file integrity monitoring on /boot and the EFI System Partition to identify unauthorized changes.
  • Inspect attached storage for unauthorized NTFS images that could be staged for exploitation.

Monitoring Recommendations

  • Forward boot-time logs, dmesg output, and UEFI firmware events to a centralized logging platform for correlation.
  • Track grub2-install, grub2-mkconfig, and efibootmgr executions on production hosts.
  • Monitor for new or modified files under /boot/efi/EFI/ across the fleet.

How to Mitigate CVE-2023-4692

Immediate Actions Required

  • Apply vendor-supplied GRUB2 updates from Red Hat, Debian, Fedora, Gentoo, and NetApp advisories listed in the references.
  • After patching, update the Secure Boot DBX revocation list (fwupdmgr or vendor tooling) so vulnerable shim and GRUB2 binaries cannot be re-loaded.
  • Restrict physical and virtual access to systems, as exploitation requires local presentation of a crafted NTFS image.
  • Disable booting from removable media in firmware where operationally feasible.

Patch Information

Red Hat addressed CVE-2023-4692 in advisories RHSA-2024:2456 and RHSA-2024:3184. Upstream fixes were published on the GNU GRUB development mailing list. Debian published a fix via the Debian LTS Security Announcement, Gentoo via GLSA 202311-14, and NetApp via NTAP-20231208-0002. Refer to the Red Hat CVE Report for component mapping.

Workarounds

  • Set a GRUB2 password to restrict editing of boot entries and limit attacker control over boot parameters.
  • Remove the NTFS module from GRUB2 builds where NTFS support is not required, eliminating the vulnerable parser.
  • Enforce full-disk encryption (LUKS) so attackers cannot tamper with the /boot partition offline.
  • Enable TPM-based measured boot and remote attestation to detect boot chain tampering.
bash
# Update GRUB2 on Red Hat Enterprise Linux
sudo dnf update grub2 grub2-common grub2-tools shim
sudo grub2-mkconfig -o /boot/grub2/grub.cfg

# Update Secure Boot revocation database
sudo fwupdmgr refresh
sudo fwupdmgr update

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeRCE

  • Vendor/TechGnu Grub2

  • SeverityHIGH

  • CVSS Score7.8

  • EPSS Probability0.00%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-122

  • CWE-787
  • Technical References
  • Red Hat Security Advisory RHSA-2024:2456

  • Red Hat Security Advisory RHSA-2024:3184

  • Red Hat CVE Report CVE-2023-4692

  • Red Hat Bug Report #2236613

  • DFIR Analysis of CVE-2023-4692 and CVE-2023-4693

  • GNU GRUB Development Mailing List Update

  • OSS-Sec Mailing List Discussion

  • Debian LTS Security Announcement

  • Fedora Package Announcement

  • Fedora Package Announcement

  • Fedora Package Announcement

  • Gentoo GLSA 202311-14

  • NetApp Security Advisory NTAP-20231208-0002
  • Related CVEs
  • CVE-2025-1125: GNU GRUB2 HFS Filesystem RCE Vulnerability

  • CVE-2025-0686: GNU GRUB2 RCE Vulnerability

  • CVE-2025-0685: GNU GRUB2 RCE Vulnerability

  • CVE-2025-0684: GNU Grub2 RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English