Description
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-37259 | A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media. |
References
History
No history.
Subscriptions
Horizondatasys
Subscribe
Uefi Bootloader
Subscribe
Microsoft
Subscribe
Windows 10
Subscribe
Windows 11
Subscribe
Windows 8.1
Subscribe
Windows Rt 8.1
Subscribe
Windows Server 2012
Subscribe
Windows Server 2016
Subscribe
Windows Server 2019
Subscribe
Windows Server 2022
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:07:16.375Z
Reserved: 2022-06-22T00:00:00.000Z
Link: CVE-2022-34302
No data.
Status : Modified
Published: 2022-08-26T18:15:09.047
Modified: 2024-11-21T07:09:15.480
Link: CVE-2022-34302
OpenCVE Enrichment
No data.
Weaknesses
EUVD