logo

Trusted Apps Sneak a Bug Into the UEFI Boot Process

ID: 73692335-0a49-5dce-9a45-1c71285342f4

STIX ID: report--73692335-0a49-5dce-9a45-1c71285342f4

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2025-01-16

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A UEFI Secure Boot bypass (CVE-2024-7344) was identified in Microsoft-signed reloader.efi used by seven real-time recovery products; the component’s custom loader reads an encrypted cloak.dat and can execute unsigned binaries at boot, enabling persistent, low-level malware if an attacker with administrator privileges replaces cloak.dat. ESET discovered the issue in July 2024, vendors patched the vulnerable applications, and Microsoft revoked the affected binaries in its January 14, 2025 Patch Tuesday update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.