Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tomer Sne-Or

Researcher fromSentinelOne
#42912of 56,330
6.7Total CVSS
Vulnerabilities · 1
PT-2023-2625
6.7
2023-05-09
Microsoft · Windows · CVE-2023-24932
**Name of the Vulnerable Software and Affected Versions** Windows versions prior to the July 9, 2024 updates **Description** A security-feature bypass issue exists in the Windows Secure Boot implementation due to errors in accessing debugging functions during the boot process. This flaw allows an attacker to bypass existing security restrictions. Specifically, the issue can be exploited by triggering a boot error to read the BitLocker decryption key from memory, as the bootloader fails to clear it. Furthermore, attackers can downgrade the bootloader to a vulnerable version to exploit this memory reading flaw, even on fully updated Windows 11 systems with Secure Boot enabled. This vulnerability has been linked to the deployment of UEFI bootkits by the FishMonger threat group to ensure persistence and stealth on targeted government systems. **Recommendations** Update Windows to the version released on or after July 9, 2024. Deploy the updated UEFI CA certificates to the system. Revoke the 2011 CA certificates and enforce the Secure Boot Security Version Number (SVN). As a temporary mitigation, suspend BitLocker and disable Secure Boot in the BIOS/UEFI settings.