Close Menu
    Trending
    • Best of AWE 2025: The most promising XR gadgets from Niantic, Sony, Android XR, and more
    • GTA Online’s next update will let you pull off a classic, if slightly dull, type of crime: money laundering
    • One of the most versatile action cameras I’ve tested isn’t from GoPro – and it’s on sale
    • Sony’s Waterproof Speaker Is Nearly Free before Prime Day, Perfect Chance to Prep for Summer Travel
    • Everything Apple revealed for iOS, macOS and more
    • The 10 open source Android apps I install on every new phone
    • The iPad I recommend to most users is only $299 right now
    • How to Watch the F1 Canadian GP 2025 on a Free Channel
    Tech Trends Today
    • Home
    • Technology
    • Tech News
    • Gadgets & Tech
    • Gaming
    • Curated Tech Deals
    • More
      • Tech Updates
      • 5G Technology
      • Accessories
      • AI Technology
      • eSports
      • Mobile Devices
      • PC Gaming
      • Tech Analysis
      • Wearable Devices
    Tech Trends Today
    Home»Tech News»Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.
    Tech News

    Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.

    GizmoHome CollectiveBy GizmoHome CollectiveJune 10, 202502 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Researchers have unearthed two publicly obtainable exploits that utterly evade protections supplied by Safe Boot, the industry-wide mechanism for making certain gadgets load solely safe working system pictures through the boot-up course of. Microsoft is taking motion to dam one exploit and permitting the opposite one to stay a viable menace.

    As a part of Tuesday’s month-to-month safety replace routine, Microsoft patched CVE-2025-3052, a Safe Boot bypass vulnerability affecting greater than 50 machine makers. Greater than a dozen modules that permit gadgets from these producers to run on Linux permit an attacker with bodily entry to show off Safe Boot and, from there, go on to put in malware that runs earlier than the working system hundreds. Such “evil maid” assaults are exactly the menace Safe Boot is designed to forestall. The vulnerability may also be exploited remotely to make infections stealthier and extra highly effective if an attacker has already gained administrative management of a machine.

    A single level of failure

    The underlying explanation for the vulnerability is a important vulnerability in a software used to flash firmware pictures on the motherboards of gadgets bought by DT Analysis, a producer of rugged cellular gadgets. It has been available on VirusTotal since final 12 months and was digitally signed in 2022, a sign it has been obtainable by way of different channels since not less than that earlier date.

    Though the module was meant to run on DT Analysis gadgets solely, most machines working both Home windows or Linux will execute it through the boot-up course of. That is as a result of the module is authenticated by “Microsoft Company UEFI CA 2011,” a cryptographic certificates that’s signed by Microsoft and comes preinstalled on affected machines. The aim of the certificates is to authenticate so-called shims for loading Linux. Producers set up it on their gadgets to make sure they’re suitable with Linux. The patch Microsoft launched Tuesday provides cryptographic hashes for 14 separate variants of the DT Analysis software to a block checklist saved within the DBX, a database itemizing signed modules which have been revoked or are in any other case untrusted.



    Source link

    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    GizmoHome Collective

    Related Posts

    Taiwan imposes export controls on Huawei, SMIC, and some of their subsidiaries, restricting their access to tech and equipment necessary for AI chip production (Debby Wu/Bloomberg)

    June 14, 2025

    A look at seven rebuttals to Apple’s paper on limitations of Large Reasoning Models, and why none make a compelling case (Gary Marcus/Marcus on AI)

    June 14, 2025

    Salt Lake City, which faces a staffing shortfall, plans to implement AI-assisted 911 call triaging to handle ~30% of about 450K non-emergency calls per year (Salt Lake Tribune)

    June 14, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Best Buy Offers HP 14-Inch Chromebook for Almost Free for Memorial Day, Nowhere to be Found on Amazon

    May 22, 2025

    The Best Sleeping Pads For Campgrounds—Our Comfiest Picks (2025)

    May 22, 2025

    Time has a new look: HUAWEI WATCH 5 debuts with exclusive watch face campaign

    May 22, 2025
    Latest Posts
    Categories
    • 5G Technology
    • Accessories
    • AI Technology
    • eSports
    • Gadgets & Tech
    • Gaming
    • Mobile Devices
    • PC Gaming
    • Tech Analysis
    • Tech News
    • Tech Updates
    • Technology
    • Wearable Devices
    Most Popular

    Best Buy Offers HP 14-Inch Chromebook for Almost Free for Memorial Day, Nowhere to be Found on Amazon

    May 22, 2025

    The Best Sleeping Pads For Campgrounds—Our Comfiest Picks (2025)

    May 22, 2025

    Time has a new look: HUAWEI WATCH 5 debuts with exclusive watch face campaign

    May 22, 2025
    Our Picks

    How to Watch the F1 Spanish Grand Prix 2025 on a Free Channel

    May 31, 2025

    iPadOS 26 makes Apple’s tablets more like Macs

    June 9, 2025

    How To Set Up GameShare On Switch 2 – Full GameShare List

    June 6, 2025
    Categories
    • 5G Technology
    • Accessories
    • AI Technology
    • eSports
    • Gadgets & Tech
    • Gaming
    • Mobile Devices
    • PC Gaming
    • Tech Analysis
    • Tech News
    • Tech Updates
    • Technology
    • Wearable Devices
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    • Curated Tech Deals
    Copyright © 2025 Gizmohome.co All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.