New UEFI Secure Boot flaw exposes systems to bootkits, patch now
ID: 77f40807-9e68-5e56-ae67-498bc8f7eb1a
STIX ID: report--77f40807-9e68-5e56-ae67-498bc8f7eb1a
Feed Name: Bleeping Computer
Threat Score
A critical UEFI Secure Boot bypass (CVE-2024-7344) was discovered in several Microsoft-signed third-party recovery UEFI applications that include a custom PE loader (reloader.efi) which can decrypt and execute unsigned binaries from cloak.dat, enabling bootkit deployment even with Secure Boot enabled; ESET published a PoC and vendor-specific vulnerable versions, and mitigations include Microsoft patches, certificate revocation, and vendor updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
