logo

New UEFI Secure Boot flaw exposes systems to bootkits, patch now

ID: 77f40807-9e68-5e56-ae67-498bc8f7eb1a

STIX ID: report--77f40807-9e68-5e56-ae67-498bc8f7eb1a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-16

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A critical UEFI Secure Boot bypass (CVE-2024-7344) was discovered in several Microsoft-signed third-party recovery UEFI applications that include a custom PE loader (reloader.efi) which can decrypt and execute unsigned binaries from cloak.dat, enabling bootkit deployment even with Secure Boot enabled; ESET published a PoC and vendor-specific vulnerable versions, and mitigations include Microsoft patches, certificate revocation, and vendor updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.