HomeLinuxMicrosoft Will Take Practically a Yr To End Patching New 0-Day Safe...

Microsoft Will Take Practically a Yr To End Patching New 0-Day Safe Boot Bug


An nameless reader quotes a report from Ars Technica: Earlier this week, Microsoft launched a patch to repair a Safe Boot bypass bug utilized by the BlackLotus bootkit we reported on in March. The unique vulnerability, CVE-2022-21894, was patched in January, however the brand new patch for CVE-2023-24932 addresses one other actively exploited workaround for methods working Home windows 10 and 11 and Home windows Server variations going again to Home windows Server 2008. The BlackLotus bootkit is the first-known real-world malware that may bypass Safe Boot protections, permitting for the execution of malicious code earlier than your PC begins loading Home windows and its many safety protections. Safe Boot has been enabled by default for over a decade on most Home windows PCs offered by corporations like Dell, Lenovo, HP, Acer, and others. PCs working Home windows 11 will need to have it enabled to satisfy the software program’s system necessities.

Microsoft says that the vulnerability may be exploited by an attacker with both bodily entry to a system or administrator rights on a system. It may possibly have an effect on bodily PCs and digital machines with Safe Boot enabled. We spotlight the brand new repair partly as a result of, not like many high-priority Home windows fixes, the replace will likely be disabled by default for not less than just a few months after it is put in and partly as a result of it can ultimately render present Home windows boot media unbootable. The repair requires modifications to the Home windows boot supervisor that may’t be reversed as soon as they have been enabled. Moreover, as soon as the fixes have been enabled, your PC will not have the ability to boot from older bootable media that does not embrace the fixes. On the prolonged checklist of affected media: Home windows set up media like DVDs and USB drives created from Microsoft’s ISO information; customized Home windows set up photographs maintained by IT departments; full system backups; community boot drives together with these utilized by IT departments to troubleshoot machines and deploy new Home windows photographs; stripped-down boot drives that use Home windows PE; and the restoration media offered with OEM PCs.

Not desirous to instantly render any customers’ methods unbootable, Microsoft will likely be rolling the replace out in phases over the subsequent few months. The preliminary model of the patch requires substantial person intervention to allow — you first want to put in Could’s safety updates, then use a five-step course of to manually apply and confirm a pair of “revocation information” that replace your system’s hidden EFI boot partition and your registry. These will make it in order that older, weak variations of the bootloader will not be trusted by PCs. A second replace will comply with in July that will not allow the patch by default however will make it simpler to allow. A 3rd replace in “first quarter 2024” will allow the repair by default and render older boot media unbootable on all patched Home windows PCs. Microsoft says it’s “in search of alternatives to speed up this schedule,” although it is unclear what that may entail.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments