16-01-2025 19:10 via it.slashdot.org

Microsoft Patches Windows To Eliminate Secure Boot Bypass Threat

Microsoft has patched a Windows vulnerability that allowed attackers to bypass Secure Boot, a critical defense against firmware infections, the company said. The flaw, tracked as CVE-2024-7344, affected Windows devices for at least seven months. Security researcher Martin Smolar discovered the vulnerability in a signed UEFI application within system recovery software from seven vendors, including Howyar.
The application, reloader.efi, circumvented standard security checks through a custom PE loa
Read more »