More

    New UEFI Secure Boot flaw exposes systems to bootkits




    • ESET finds bug in a UEFI application allowing malicious actors to bypass UEFI Secure Boot
    • The move grants criminals the ability to deploy bootkits to affected systems
    • Microsoft addressed the bug in January 2025 Patch Tuesday update

    An unnamed, but apparently popular, UEFI application, was signed with a vulnerable certificate, allowing threat actors to bypass UEFI Secure Boot and deploy bootkits to target endpoints.

    Cybersecurity researchers at ESET discovered the bug and reported it to the CERT Coordination Center – Microsoft has issued a fix in this month’s Patch Tuesday cumulative update, which was released on January 14, 2025, but all Windows users are advised to apply the patch as soon as possible.

    https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img