Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344
ID: 48a8a1ad-ff00-5c65-acb1-389a3d5587bd
STIX ID: report--48a8a1ad-ff00-5c65-acb1-389a3d5587bd
Feed Name: WeLiveSecurity (ESET Research)
ESET disclosed CVE-2024-7344, a UEFI Secure Boot bypass in Microsoft-signed third-party recovery bootloaders (notably reloader.efi) that uses a custom PE loader to load an unsigned UEFI binary embedded in cloak.dat, enabling boot-time execution of untrusted code and potential deployment of UEFI bootkits; affected vendors released fixes and Microsoft revoked the vulnerable binaries on 2025-01-14, and mitigations include applying Microsoft UEFI revocations and vendor updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
