Tech

New UEFI Secure Boot flaw exposes systems to bootkits

Share
Share


  • ESET finds bug in a UEFI application allowing malicious actors to bypass UEFI Secure Boot
  • The move grants criminals the ability to deploy bootkits to affected systems
  • Microsoft addressed the bug in January 2025 Patch Tuesday update

An unnamed, but apparently popular, UEFI application, was signed with a vulnerable certificate, allowing threat actors to bypass UEFI Secure Boot and deploy bootkits to target endpoints.

Cybersecurity researchers at ESET discovered the bug and reported it to the CERT Coordination Center – Microsoft has issued a fix in this month’s Patch Tuesday cumulative update, which was released on January 14, 2025, but all Windows users are advised to apply the patch as soon as possible.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Can a foreign government hack WhatsApp? A cybersecurity expert explains how that might work
Tech

Can a foreign government hack WhatsApp? A cybersecurity expert explains how that might work

Credit: Pixabay/CC0 Public Domain Earlier today, Iranian officials urged the country’s citizens...

What could have caused the Air India crash? An expert examines the proposed failure scenarios
Tech

What could have caused the Air India crash? An expert examines the proposed failure scenarios

Credit: Ahmed Muntasir from Pexels The recent crash of an Air India...