Trusted Apps Sneak a Bug Into the UEFI Boot Process
ID: 73692335-0a49-5dce-9a45-1c71285342f4
STIX ID: report--73692335-0a49-5dce-9a45-1c71285342f4
Feed Name: Dark Reading
A UEFI Secure Boot bypass (CVE-2024-7344) was identified in Microsoft-signed reloader.efi used by seven real-time recovery products; the component’s custom loader reads an encrypted cloak.dat and can execute unsigned binaries at boot, enabling persistent, low-level malware if an attacker with administrator privileges replaces cloak.dat. ESET discovered the issue in July 2024, vendors patched the vulnerable applications, and Microsoft revoked the affected binaries in its January 14, 2025 Patch Tuesday update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
