Tech

New UEFI Secure Boot flaw exposes systems to bootkits

Share
Share


  • ESET finds bug in a UEFI application allowing malicious actors to bypass UEFI Secure Boot
  • The move grants criminals the ability to deploy bootkits to affected systems
  • Microsoft addressed the bug in January 2025 Patch Tuesday update

An unnamed, but apparently popular, UEFI application, was signed with a vulnerable certificate, allowing threat actors to bypass UEFI Secure Boot and deploy bootkits to target endpoints.

Cybersecurity researchers at ESET discovered the bug and reported it to the CERT Coordination Center – Microsoft has issued a fix in this month’s Patch Tuesday cumulative update, which was released on January 14, 2025, but all Windows users are advised to apply the patch as soon as possible.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
A trio of studies could help Puerto Rico’s energy system weather future storms
Tech

A trio of studies could help Puerto Rico’s energy system weather future storms

Schematic diagram of the CRESCENT model. The proposed CRESCENT model enables the...

AI paves the way toward green cement
Tech

AI paves the way toward green cement

When cement is mixed with water, sand and gravel, it becomes concrete—the...

Humanoid robot achieves controlled flight using jet engines and AI-powered systems
Tech

Humanoid robot achieves controlled flight using jet engines and AI-powered systems

iRonCub3 is the technological evolution of previous prototypes and is based on...