Cyber security experts sound the alarm: A dangerous new vulnerability has been discovered in the UEFI boot system that allows attackers to completely bypass the Secure Boot protection mechanism. The fact that even a complete reinstallation of the operating system cannot rid the computer of this threat is particularly alarming.
The new vulnerability, codenamed CVE-2024-7344 Howyar Taiwan Secure Boot Bypass, is associated with critical flaws in the PE boot loader. Attackers can use this “hole” to load any uncertified UEFI files. The most dangerous thing is that malware installed through this vulnerability becomes practically invisible to security systems.
Cybercriminals get the opportunity to replace the standard operating system boot loader on the EFI partition with their malicious version. Such a modification contains an encrypted XOR PE image that completely bypasses the Secure Boot system. As a result, installed antivirus programs and other protection tools are ineffective against this threat.
Of particular concern is the fact that the vulnerability is actively exploited through well-known system recovery tools. Among the compromised programs:
Microsoft and ESET have already responded to the vulnerability. The companies have implemented urgent security measures, including revoking the certificates of compromised software through the latest Windows update. Experts strongly recommend that users immediately update their Windows operating system and install the latest versions of all programs they use.
The US has handed over the first 28 M1A2SEPv3 "Abrams" tanks to Poland, which will…
Thanks to the new technology, laptops, drones, electric cars and other equipment will become more…
The demand for specialists in the field of artificial intelligence (AI) is growing rapidly. According…
A resident was tried in Zhytomyr for obstructing the mobilization. He reported on social networks…
Popular social network TikTok may disappear from Europe due to security threats European countries are…
London has no plans to ban the TikTok social network, the British government said on…