← back
CVE-2024-38011

Secure Boot Security Feature Bypass Vulnerability

CVSS 8 HIGHEPSS 1.3%CWE-130
In short

A flaw in Secure Boot allows attackers to bypass security protections designed to ensure only trusted code runs on system startup. This undermines the entire boot security mechanism that protects against malicious firmware and rootkits.

Technical detail

This vulnerability enables bypass of Secure Boot verification mechanisms through improper validation of signed code during the boot process. An attacker with physical access or firmware write permissions can leverage inadequate cryptographic verification (CWE-130) to load unsigned or maliciously signed code, compromising the integrity of the entire system stack.

Summary generated and translated by AI from the official description.
Secure Boot Security Feature Bypass Vulnerability
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →