PT-2023-2625 · Microsoft · Windows
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows versions prior to the July 9, 2024 updates
Description
A security-feature bypass issue exists in the Windows Secure Boot implementation due to errors in accessing debugging functions during the boot process. This flaw allows an attacker to bypass existing security restrictions. Specifically, the issue can be exploited by triggering a boot error to read the BitLocker decryption key from memory, as the bootloader fails to clear it. Furthermore, attackers can downgrade the bootloader to a vulnerable version to exploit this memory reading flaw, even on fully updated Windows 11 systems with Secure Boot enabled. This vulnerability has been linked to the deployment of UEFI bootkits by the FishMonger threat group to ensure persistence and stealth on targeted government systems.
Recommendations
Update Windows to the version released on or after July 9, 2024.
Deploy the updated UEFI CA certificates to the system.
Revoke the 2011 CA certificates and enforce the Secure Boot Security Version Number (SVN).
As a temporary mitigation, suspend BitLocker and disable Secure Boot in the BIOS/UEFI settings.
Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows