|
||
ESET Research Discovers UEFI Secure Boot Bypass Vulnerability
| ||
Dubai, United Arab Emirates
ESET researchers have discovered a vulnerability, affecting the majority of UEFI-based systems, that allows actors to bypass UEFI Secure Boot. This vulnerability, assigned CVE-2024-7344, was found in a UEFI application signed by Microsoft’s “Microsoft Corporation UEFI CA 2011” third-party UEFI certificate. Exploitation of this vulnerability can lead to the execution of untrusted code during system boot, enabling potential attackers to easily deploy malicious UEFI bootkits (such as Bootkitty or BlackLotus) even on systems with UEFI Secure Boot enabled, regardless of the operating system installed.
ESET Research discovers UEFI Secure Boot bypass vulnerability
For more information, visit www.eset.com or follow us on LinkedIn, Facebook, and X. |
||
|
||||||||||||||||
| ||||||||||||||||