CVE-2024-7344: Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass
Other sources
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
— MITRE
This CVE was assigned by CERT CC. The purpose of this document is to attest to the fact that the products listed in the Security Updates table have been updated to protect against this vulnerability.
— Microsoft
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7344?
CVE-2024-7344 is classified as a high-severity vulnerability impacting UEFI secure boot.
How do I fix CVE-2024-7344?
To fix CVE-2024-7344, you must apply the security updates provided by Microsoft for the affected Windows products.
Which products are affected by CVE-2024-7344?
CVE-2024-7344 affects several versions of Windows, including Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025.
What kind of attacks can CVE-2024-7344 enable?
CVE-2024-7344 can enable attackers to bypass secure boot mechanisms, potentially leading to the installation of malicious boot kits.
How can I determine if my system is vulnerable to CVE-2024-7344?
You can determine if your system is vulnerable to CVE-2024-7344 by checking if it is running a version of Windows listed as affected and verifying if the security updates have been applied.