New UEFI vulnerability bypasses Secure Boot — bootkits stay undetected even after OS re-install

New UEFI vulnerability bypasses Secure Boot — bootkits stay undetected even after OS re-install

January 18, 2025



A new UEFI vulnerability has been discovered that is spread through multiple system recovery tools. Bleeping Computer reports that the vulnerability enables attackers to bypass Secure Boot and deploy bootkits that can be invisible to the operating system. Microsoft has officially flagged the vulnerability with the codename CVE-2024-7344 Howyar Taiwan Secure Boot Bypass.

The culprit purportedly comes from a customer PE loader, which allows any UEFI binary to be loaded, even unsigned ones. This is due to the vulnerability allegedly not relying on trusted services such as LoadImage and StartImage.



Source link

You May Also Like…

0 Comments