Microsoft has blocked Secure Boot mitigations for the BlackLotus (CVE-2023-24932) vulnerability on some PCs. The block affects Windows Server 2012 and 2012 R2 systems due to incompatibilities with TPM
Uefi secure boot vulnerability RSS
Nearly all motherboard makes were found vulnerable to the LogoFAIL security flaw at the end of last year. And at long last, AMD's vendor partners are finally beginning to roll out patched firmware.
Microsoft released its Patch Tuesday updates earlier today for both Windows 11 and 10. In a follow-up, it added that these updates bring the latest Dynamic SafeOS packages against Secure Boot flaws.
Microsoft recently began patching UEFI bootkit vulnerabilities with this month's Patch Tuesday update. The company has now released a helpful guide about blocking such Windows boot managers.
Microsoft has patched UEFI Secure Boot security vulnerability called BlackLotus with its latest Update Tuesday released earlier today. The fix is available on Windows 10, Windows 11, and Servers.
Microsoft has published some helpful guidance against the BlackLotus UEFI bootkit vulnerability that can bypass Secure Boot, VBS, BitLocker, Windows Defender, and more to infect updated Windows PCs.
MSI motherboards, from both Intel and AMD, have been vulnerable due to a broken Secure Boot firmware setting issue. The bug would allow potentially malicious files to boot into an affected system.
With Patch Tuesday recently, Microsoft released the KB5012170 update which adds new vulnerable UEFI signatures to the Secure Boot DBX. The newly added signatures are related to the GRUB vulnerability.
Several popular Lenovo consumer models, including IdeaPad, Legion, and more, have been found to be vulnerable to UEFI firmware security bugs. The vulnerabilities can lead to privilege of escalation.
A newly discovered flaw in Secure Boot affects almost all Linux distros and Windows devices that leverage the UEFI boot tech. If the flow is exploited, attackers can gain full control of the system.