logo

ESET detailed a flaw that could allow a bypass of the Secure Boot in UEFI systems

ID: 9dfbc4f7-6cf0-5440-b546-21cbda3224ef

STIX ID: report--9dfbc4f7-6cf0-5440-b546-21cbda3224ef

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2025-01-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

ESET disclosed CVE-2024-7344, a now-patched UEFI Secure Boot bypass in multiple third-party real-time recovery UEFI applications that used a custom PE loader, enabling unsigned UEFI binaries to be loaded from a crafted cloak.dat and allowing deployment of bootkits; vendors were notified, affected binaries revoked in Microsoft’s January 14, 2025 update, and a proof-of-concept was published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.