PT-2023-2625 · Microsoft · Windows

·

CVE-2023-24932

·

Published

2023-05-09

·

Updated

2026-08-30

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows versions prior to the July 9, 2024 updates
Description A security-feature bypass issue exists in the Windows Secure Boot implementation due to errors in accessing debugging functions during the boot process. This flaw allows an attacker to bypass existing security restrictions. Specifically, the issue can be exploited by triggering a boot error to read the BitLocker decryption key from memory, as the bootloader fails to clear it. Furthermore, attackers can downgrade the bootloader to a vulnerable version to exploit this memory reading flaw, even on fully updated Windows 11 systems with Secure Boot enabled. This vulnerability has been linked to the deployment of UEFI bootkits by the FishMonger threat group to ensure persistence and stealth on targeted government systems.
Recommendations Update Windows to the version released on or after July 9, 2024. Deploy the updated UEFI CA certificates to the system. Revoke the 2011 CA certificates and enforce the Secure Boot Security Version Number (SVN). As a temporary mitigation, suspend BitLocker and disable Secure Boot in the BIOS/UEFI settings.

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02465
CVE-2023-24932

Affected Products

Windows