A vulnerability was reported
in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014
that could allow a privileged attacker with local access to modify the boot manager and escalate privileges.
Metrics
Affected Vendors & Products
Solution
Concerned customers can follow Microsoft's guidance to apply the April 9, 2024 Windows security updates. Please refer to KB5025885 to enable the latest protections: https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocatio... https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-132277 |
![]() ![]() ![]() |
No history.

Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-01T23:06:25.336Z
Reserved: 2024-01-18T15:28:42.477Z
Link: CVE-2024-23593

Updated: 2024-08-01T23:06:25.336Z

Status : Awaiting Analysis
Published: 2024-04-15T18:15:10.353
Modified: 2024-11-21T08:57:58.400
Link: CVE-2024-23593

No data.

No data.