Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Encore ROG 12RK-FB teardrop camper with pop-up wet bathroom tent
    • Munich-based encosa raises €25 million to bring battery storage to German SMEs
    • Websites Can Now Spy on You Through Your Hard Drive
    • Kalshi debuts regulated crypto perpetual futures
    • Apple Will Reportedly Add Bill-Splitting Feature to iOS 27
    • Escaping the Valley of Choice in BI
    • SEO headline New urine test uses gut biomarkers to identify autism earlier
    • Socceroos legend Tim Cahill backs sports swag design platform Nardo in $1 million pre-Seed raise
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Microsoft patches Windows to eliminate Secure Boot bypass threat
    News

    Microsoft patches Windows to eliminate Secure Boot bypass threat

    Editor Times FeaturedBy Editor Times FeaturedJanuary 16, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    For the previous seven months—and certain longer—an industry-wide normal that protects Home windows gadgets from firmware infections may very well be bypassed utilizing a easy approach. On Tuesday, Microsoft lastly patched the vulnerability. The standing of Linux programs continues to be unclear.

    Tracked as CVE-2024-7344, the vulnerability made it attainable for attackers who had already gained privileged entry to a tool to run malicious firmware throughout bootup. These kind of assaults might be significantly pernicious as a result of infections cover contained in the firmware that runs at an early stage, earlier than even Home windows or Linux has loaded. This strategic place permits the malware to evade defenses put in by the OS and offers it the flexibility to outlive even after arduous drives have been reformatted. From then on, the ensuing “bootkit” controls the working system begin.

    In place since 2012, Safe Boot is designed to forestall these kinds of assaults by making a chain-of-trust linking every file that will get loaded. Every time a tool boots, Safe Boot verifies that every firmware part is digitally signed earlier than it’s allowed to run. It then checks the OS bootloader’s digital signature to make sure that it is trusted by the Safe Boot coverage and hasn’t been tampered with. Safe Boot is constructed into the UEFI—brief for Unified Extensible Firmware Interface—the successor to the BIOS that’s accountable for booting trendy Home windows and Linux gadgets.

    An unsigned UEFI app lurks

    Final yr, researcher Martin Smolár with safety agency ESET observed one thing interested by SysReturn, a real-time system restoration software program suite out there from Howyar Applied sciences. Buried deep inside was an XOR-encoded UEFI utility named reloader.efi, which was digitally signed after in some way passing Microsoft’s internal review process for third-party UEFI apps.

    Fairly than invoking the UEFI features LoadImage and StartImage for performing the Safe Boot course of, reloader.efi used a customized PE loader. This tradition loader didn’t carry out the required checks. As Smolár dug additional, he discovered that reloader.efi was current not solely in Howyar’s SysReturn, but in addition in restoration software program from six different suppliers. The entire checklist is:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026

    Manchester gambling raid sparks wider enforcement focus

    June 2, 2026

    Burbank laboratory owner sentenced over Medicare gambling fraud

    June 1, 2026

    Salesforce has a stake in Anthropic worth ~$5B; Salesforce first invested about $50M in an early 2023 round and has continually invested in rounds since (Brody Ford/Bloomberg)

    June 1, 2026

    New York City-based Mecka AI, which trains robots with human data sourced from body sensors and iPhones, raised $60M, including a $25M Series A (Ben Weiss/Fortune)

    June 1, 2026

    SpaceX will reserve up to 5% of its Class A shares for select employees and executives’ friends and family; 60%+ of shares have an extended lock-up (Charles Capel/Bloomberg)

    June 1, 2026

    Comments are closed.

    Editors Picks

    Encore ROG 12RK-FB teardrop camper with pop-up wet bathroom tent

    June 2, 2026

    Munich-based encosa raises €25 million to bring battery storage to German SMEs

    June 2, 2026

    Websites Can Now Spy on You Through Your Hard Drive

    June 2, 2026

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Florida Gaming Control Commission seizes 22 illegal gambling machines

    November 25, 2025

    GAMING: Indie games are slowly dominating PAX Australia

    October 24, 2025

    Innovative tiny house with rotating rooms redefines space

    July 22, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.