Skip to content
Critical UEFI Secure Boot Bypass Vulnerability Discovered

Critical UEFI Secure Boot Bypass Vulnerability Discovered

First seen 18 Jun 2026, 20:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 19, 2026 at 20:23 UTC
  • CVE-2024-7344 allows UEFI Secure Boot bypass on many systems.
  • Attackers can execute untrusted code during the early boot phase.
  • Affected applications include those from multiple vendors, now patched.

ESET researchers identified a significant vulnerability, CVE-2024-7344, allowing bypass of UEFI Secure Boot on numerous systems. This flaw affects UEFI applications signed by multiple vendors, enabling attackers to execute untrusted code during the boot process. The vulnerability arises from a custom PE loader that permits loading unsigned UEFI binaries. Affected applications are part of recovery software from various vendors, including Howyar Technologies and Greenware Technologies. The issue was disclosed to CERT/CC in June 2024, leading to a coordinated response and revocation of vulnerable binaries by Microsoft in January 2025. System administrators are advised to update the UEFI Forbidden Signature Database (DBX) to mitigate risks. The vulnerability poses a serious threat as it can lead to persistent platform compromise before the OS initializes.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2022-08-26
CVE-2022-34302 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-06-01
Vulnerability discovered by ESET
ESET identified CVE-2024-7344, allowing bypass of UEFI Secure Boot on affected systems.
www.welivesecurity.com
2024-06-15
Reported to CERT/CC
ESET reported the vulnerability to CERT/CC, which coordinated with affected vendors for remediation.
www.welivesecurity.com
2025-01-14
Microsoft revokes vulnerable binaries
Microsoft revoked the affected binaries during the January Patch Tuesday update, addressing CVE-2024-7344.
www.welivesecurity.com
2025-01-14
CVE-2024-7344 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
VU#457458 published by CERT/CC
CERT/CC published VU#457458, detailing the vulnerability and urging updates to the UEFI DBX.
Kb.Cert
2026-06-19
Guidance issued for UEFI DBX updates
Urgent recommendations were made to update the UEFI Forbidden Signature Database to mitigate risks.
Gbhackers

More articles in this cluster (4)

Following this threat?

Track BlackLotus, Greenware Technologies and CVE-2022-34302 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed