Microsoft Addresses Multiple Security Vulnerabilities with New Patches.

TL;DR Summary
Microsoft has released a patch to fix a Secure Boot bypass bug used by the BlackLotus bootkit. The new patch for CVE-2023-24932 addresses another actively exploited workaround for systems running Windows 10 and 11 and Windows Server versions going back to Windows Server 2008. The update will be disabled by default for at least a few months after it's installed and will eventually render current Windows boot media unbootable. Microsoft will be rolling the update out in phases over the next few months to prevent any users' systems from becoming unbootable.
- Microsoft patches Secure Boot flaw, but won’t enable fix by default until early 2024 Ars Technica
- Experts Detail New Zero-Click Windows Vulnerability for NTLM Credential Theft The Hacker News
- Microsoft releases optional fix for actively exploited Secure Boot vulnerability TechSpot
- Bootkit zero-day fix – is this Microsoft’s most cautious patch ever? Naked Security
- Microsoft patches bypass for recently fixed Outlook zero-click bug BleepingComputer
Reading Insights
Total Reads
0
Unique Readers
13
Time Saved
3 min
vs 4 min read
Condensed
87%
705 → 91 words
Want the full story? Read the original article
Read on Ars Technica