Cyber security experts sound the alarm: A dangerous new vulnerability has been discovered in the UEFI boot system that allows attackers to completely bypass the Secure Boot protection mechanism. The fact that even a complete reinstallation of the operating system cannot rid the computer of this threat is particularly alarming.
The new vulnerability, codenamed CVE-2024-7344 Howyar Taiwan Secure Boot Bypass, is associated with critical flaws in the PE boot loader. Attackers can use this “hole” to load any uncertified UEFI files. The most dangerous thing is that malware installed through this vulnerability becomes practically invisible to security systems.
Cybercriminals get the opportunity to replace the standard operating system boot loader on the EFI partition with their malicious version. Such a modification contains an encrypted XOR PE image that completely bypasses the Secure Boot system. As a result, installed antivirus programs and other protection tools are ineffective against this threat.
Of particular concern is the fact that the vulnerability is actively exploited through well-known system recovery tools. Among the compromised programs:
Microsoft and ESET have already responded to the vulnerability. The companies have implemented urgent security measures, including revoking the certificates of compromised software through the latest Windows update. Experts strongly recommend that users immediately update their Windows operating system and install the latest versions of all programs they use.
In a small, modest town, where everyone knew everyone, and life went on the rhythm…
My mother, a teacher by calling, spent her whole life in school walls, where vigilance…
Two years ago, Wanda was the wife of my son, Kacper. Their story began like…
On Monday, Poland was circulated by surprising news about Karol Nawrocki, former director of the…
< img src = "/uploads/blogs/20/02/ib-fqglf0ghl_f275e194.png" Alt = "MacBook Air will receive a powerful upgrade already…
< img src = "/uploads/blogs/57/cb/ib-1ikrpq930_6FC93162.jpg" Alt = "Ukrainian developers presented a unique drone kamikadze with…