A vulnerability in trusted system recovery programs could allow privileged attackers to inject malware directly into the system startup process in Unified Extensible Firmware Interface (UEFI) devices. Seven real-time recovery products — Howyar SysReturn, Greenware GreenGuard, Radix SmartRecovery, Sanfong EZ-back System, WASAY eRecoveryRX, CES NeoImpact, and SignalComputer HDD King — all make use of "reloader.efi," the Microsoft-signed Extensible Firmware Interface (EFI) file at issue. The problem, ESET explains in a new report, is that reloader.efi uses a custom loader that enables the application to load even unsigned binaries during the boot process. In essence, it's a backdoor for sneaking any kind of file into a system's startup, past UEFI Secure Boot. The issue has been assigned CVE-2024-7344, and earned a "medium" 6.5 Common Vulnerability Scoring System (CVSS) rating, as it requires administrator privileges to exploit. The standard way to load, prepare, and execute UEFI images in system memory is with the autological LoadImage and StartImage functions. The Microsoft-approved "reloader" application goes its own way, using a custom mechanism that allows it to load any binary, trusted or otherwise, at startup. "Maybe it's a lack of secure coding awareness," Martin Smolár, malware researcher at ESET, guesses of the developers' motives in implementing the custom loader. "Or maybe it's because they found it convenient to create such a functionality. Because when a developer m...
Trusted Apps Sneak a Bug Into the UEFI Boot Process
Dark Reading
·Nate Nelson
·Published Jan 16, 2025
·Updated
Affected Software
16 affected components
Howyar Sysreturn
Greenware Greenguard
Radix SmartRecovery
Sanfong Ez-back System
Wasay Erecoveryrx
CES NeoImpact
Signalcomputer Hdd King
Microsoft reloader.efi
Howyar Sysreturn
Greenware Greenguard
Radix SmartRecovery
Sanfong Ez-back System
Wasay Erecoveryrx
CES NeoImpact
Signalcomputer Hdd King
Microsoft Extensible Firmware Interface=reloader.efi