Tag

Cve 2023 24932

All articles tagged with #cve 2023 24932

Microsoft's Ongoing Battle with Security Flaws: Latest Updates and Fixes.
technology3 years ago

Microsoft's Ongoing Battle with Security Flaws: Latest Updates and Fixes.

Microsoft has released a patch to fix a Secure Boot bypass bug used by the BlackLotus bootkit, which is the first-known real-world malware that can bypass Secure Boot protections. The new patch for CVE-2023-24932 addresses another actively exploited workaround for systems running Windows 10 and 11 and Windows Server versions going back to Windows Server 2008. However, the update will be disabled by default for at least a few months after it's installed and will eventually render current Windows boot media unbootable. Microsoft will be rolling the update out in phases over the next few months to avoid rendering any users' systems unbootable.

Microsoft's May 2023 Patch Tuesday addresses critical vulnerabilities and zero-day exploits.
cybersecurity3 years ago

Microsoft's May 2023 Patch Tuesday addresses critical vulnerabilities and zero-day exploits.

Microsoft's May Patch Tuesday includes 38 security fixes, with six deemed critical. Two of the vulnerabilities have already been exploited by attackers, including a Win32k elevation of privilege flaw and a Secure Boot security feature bypass vulnerability used by the BlackLotus bootkit. A third vulnerability, a Windows OLE Remote Code Execution flaw, has been publicly disclosed. Adobe released one security bulletin for Adobe Substance 3D Painter, while SAP released 25 new and updated security patches, including two Hot News and nine High Priority notes. Android's latest security bulletin resolved 18 flaws, with the most severe requiring user interaction to exploit.