ESET detailed a flaw that could allow a bypass of the Secure Boot in UEFI systems
ID: 9dfbc4f7-6cf0-5440-b546-21cbda3224ef
STIX ID: report--9dfbc4f7-6cf0-5440-b546-21cbda3224ef
Feed Name: Security Affairs
Threat Score
ESET disclosed CVE-2024-7344, a now-patched UEFI Secure Boot bypass in multiple third-party real-time recovery UEFI applications that used a custom PE loader, enabling unsigned UEFI binaries to be loaded from a crafted cloak.dat and allowing deployment of bootkits; vendors were notified, affected binaries revoked in Microsoft’s January 14, 2025 update, and a proof-of-concept was published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
