Microsoft releases optional fix for two zero-day vulnerabilities.

TL;DR Summary
Microsoft has released an optional security update to address a Secure Boot zero-day vulnerability exploited by BlackLotus UEFI malware to infect fully patched Windows systems. The security flaw was used to bypass patches released for CVE-2022-21894, another Secure Boot bug abused in BlackLotus attacks last year. The CVE-2023-24932 security patches released today are only available for supported versions of Windows 10, Windows 11, and Windows Server. Customers must undergo a procedure requiring multiple manual steps to update bootable media and apply revocations before enabling this update.
- Microsoft issues optional fix for Secure Boot zero-day used by malware BleepingComputer
- Two Microsoft Windows bugs under attack, one in Secure Boot with a manual fix The Register
- Microsoft Patches 2 Zero-Day Vulnerabilities DARKReading
- Microsoft May 2023 Patch Tuesday fixes 3 zero-days, 38 flaws BleepingComputer
- May 2023 Patch Tuesday: Updates and Analysis CrowdStrike
Reading Insights
Total Reads
0
Unique Readers
25
Time Saved
3 min
vs 4 min read
Condensed
86%
609 → 86 words
Want the full story? Read the original article
Read on BleepingComputer