Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability

BID:67947

Info

Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability

Bugtraq ID: 67947
Class: Design Error
CVE: CVE-2014-2961
Remote: No
Local: Yes
Published: Jun 09 2014 12:00AM
Updated: Jun 09 2014 12:00AM
Credit: Corey Kallenberg, Xeno Kovah, John Butterworth, and Sam Cornwell of MITRE Corporation
Vulnerable: Intel Server System R1000SP Family 0
Intel Server System R1000RP Family 0
Intel Server System R1000JP Family 0
Intel Server System R1000GZ Family 0
Intel Server System R1000GL Family 0
Intel Server System R1000EP Family 0
Intel Server System R1000BB Family 0
Intel Server System P4304BT 0
Intel Server System P4000SC Family 0
Intel Server System P4000RP Family 0
Intel Server System P4000IP Family 0
Intel Server System P4000CP Family 0
Intel Server System H2000WP Family 0
Intel Server System H2000LP Family 0
Intel Server System H2000JF Family 0
Intel Server Board S5520UR 0
Intel Server Board S5520HCT 0
Intel Server Board S5520HC 0
Intel Server Board S5500WB 0
Intel Server Board S5500HCV 0
Intel Server Board S5500BC 0
Intel Server Board S4600LT Family 0
Intel Server Board S4600LH Family 0
Intel Server Board S3420GP 0
Intel Server Board S2600WP 0
Intel Server Board S2600JF 0
Intel Server Board S2600IP Family 0
Intel Server Board S2600GZ 0
Intel Server Board S2600GL 0
Intel Server Board S2600CP Family 0
Intel Server Board S2600CO Family 0
Intel Server Board S2400SC Family 0
Intel Server Board S2400LP Family 0
Intel Server Board S2400GP Family 0
Intel Server Board S2400EP Family 0
Intel Server Board S2400BB 0
Intel Server Board S1600JP Family 0
Intel Server Board S1400SP Family 0
Intel Server Board S1400FP Family 0
Intel Server Board S1200RP 0
Intel Server Board S1200KP 0
Intel Server Board S1200BT 0
Intel Quark SoC X1000 Transportation Reference Design 1.0.1
Intel Quark SoC X1000 Industrial/Energy Reference Design 1.0.1
Intel NUC with Intel Core i5 processor (D54250WYKH) 0
Intel NUC with Intel Core i5 processor (D54250WYK) 0
Intel NUC with Intel Core i3 processor (D34010WYKH) 0
Intel NUC with Intel Core i3 processor (D34010WYK) 0
Intel NUC with Intel Core i5 processor (D53427RKE, D53427HYE) 0
Intel NUC with Intel Celeron Processor (DN2820FYKH) 0
Intel NUC with Intel Atom Processor (DE3815TYKHE) 0
Intel Galileo board Generation 2 (pre-release) 1.0.1
Intel Galileo board 1.0.1
Not Vulnerable:

Discussion

Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability

Multiple products that implement UEFI secure boot are prone to a local security-bypass vulnerability.

Attackers with physical access to the computer running the vulnerable firmware can exploit this issue to bypass certain security restrictions and trigger denial-of-service conditions.

NOTE: Very limited information is currently available regarding this issue. We will update this BID as more information emerges.

Exploit / POC

Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability

An attacker with physical access to the computer can exploit this issue.

The researcher who discovered this issue has created a functional exploit. The exploit is otherwise not publicly available. Please see the references for more information.

Solution / Fix

Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability

Solution:
Updates are available. Please see the references or vendor advisory for more information.

References

Multiple Products UEFI Secure Boot CVE-2014-2961 Local Security Bypass Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report