New UEFI Secure Boot Vulnerability Could Allow Attackers to Load Malicious Bootkits
Information has surfaced regarding a security flaw that has been fixed and may enable a workaround for Unified Extensible Firmware Interface (UEFI) computers' Secure Boot mechanism.
According to a recent ESET research published with The Hacker News, the vulnerability, which has been issued the CVE identifier CVE-2024-7344 (CVSS score: 6.7), is present in a UEFI application that is signed by Microsoft's "Microsoft Corporation UEFI CA 2011" third-party UEFI certificate.
If the vulnerability is successfully exploited, it may result in the execution of untrusted code during system boot, which would allow attackers to install malicious UEFI bootkits on computers with Secure Boot enabled, regardless of the operating system that is installed read more about New UEFI Secure Boot Vulnerabili...

