First published: Mon May 05 2025(Updated: )
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
Credit: 8338d8cb-57f7-4252-abc0-96fd13e98d21
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.