Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
https://edk2-docs.gitbook.io/security-advisory/bootguard-toctou-vulnerability