www.welivesecurity.com
Critical UEFI Secure Boot Bypass Vulnerability Discovered
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
ESET researchers identified a significant vulnerability, CVE-2024-7344, allowing bypass of UEFI Secure Boot on numerous systems. This flaw affects UEFI applications signed by multiple vendors, enabling attackers to execute untrusted code during the boot process. The vulnerability arises from a custom PE loader that permits loading unsigned UEFI binaries. Affected applications are part of recovery software from various vendors, including Howyar Technologies and Greenware Technologies. The issue was disclosed to CERT/CC in June 2024, leading to a coordinated response and revocation of vulnerable binaries by Microsoft in January 2025. System administrators are advised to update the UEFI Forbidden Signature Database (DBX) to mitigate risks. The vulnerability poses a serious threat as it can lead to persistent platform compromise before the OS initializes.
Key Points: • CVE-2024-7344 allows UEFI Secure Boot bypass on many systems. • Attackers can execute untrusted code during the early boot phase. • Affected applications include those from multiple vendors, now patched.