Critical UEFI Secure Boot Bypass Vulnerability Discovered
ID: b388122f-85af-5734-a757-768d3b6c7dc9
STIX ID: report--b388122f-85af-5734-a757-768d3b6c7dc9
Feed Name: ThreatCluster
Threat Score
ESET researchers disclosed CVE-2024-7344, a critical UEFI Secure Boot bypass affecting recovery applications from multiple vendors; the flaw stems from a custom PE loader that permits unsigned UEFI binaries, enabling attackers to run untrusted code before the OS boots. The issue was coordinated with CERT/CC and Microsoft, which revoked vulnerable binaries and advised administrators to update the UEFI Forbidden Signature Database (DBX) to mitigate persistent platform compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
