← back
CVE-2024-38011highCWE-130

Secure Boot Security Feature Bypass Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8epss 1.3%
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Secure Boot allows attackers to bypass security protections designed to ensure only trusted code runs on system startup. This undermines the entire boot security mechanism that protects against malicious firmware and rootkits.

Technical detail

This vulnerability enables bypass of Secure Boot verification mechanisms through improper validation of signed code during the boot process. An attacker with physical access or firmware write permissions can leverage inadequate cryptographic verification (CWE-130) to load unsigned or maliciously signed code, compromising the integrity of the entire system stack.

Summary generated and translated by AI from the official description.
Secure Boot Security Feature Bypass Vulnerability
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C