Microsoft releases optional fix for two zero-day vulnerabilities.

1 min read
Source: BleepingComputer
Microsoft releases optional fix for two zero-day vulnerabilities.
Photo: BleepingComputer
TL;DR Summary

Microsoft has released an optional security update to address a Secure Boot zero-day vulnerability exploited by BlackLotus UEFI malware to infect fully patched Windows systems. The security flaw was used to bypass patches released for CVE-2022-21894, another Secure Boot bug abused in BlackLotus attacks last year. The CVE-2023-24932 security patches released today are only available for supported versions of Windows 10, Windows 11, and Windows Server. Customers must undergo a procedure requiring multiple manual steps to update bootable media and apply revocations before enabling this update.

Share this article

Reading Insights

Total Reads

0

Unique Readers

25

Time Saved

3 min

vs 4 min read

Condensed

86%

60986 words

Want the full story? Read the original article

Read on BleepingComputer