logo

Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344

ID: 48a8a1ad-ff00-5c65-acb1-389a3d5587bd

STIX ID: report--48a8a1ad-ff00-5c65-acb1-389a3d5587bd

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-01-16

Date Updated: 2026-05-01

...
...

ESET disclosed CVE-2024-7344, a UEFI Secure Boot bypass in Microsoft-signed third-party recovery bootloaders (notably reloader.efi) that uses a custom PE loader to load an unsigned UEFI binary embedded in cloak.dat, enabling boot-time execution of untrusted code and potential deployment of UEFI bootkits; affected vendors released fixes and Microsoft revoked the vulnerable binaries on 2025-01-14, and mitigations include applying Microsoft UEFI revocations and vendor updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.