← Back

CVE-2022-34303

nvd nist
Published: Aug 26, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

Affected (19)

1 product
Uefi Bootloader
1 product
Enterprise Linux
8 products
Windows 10
Windows 11
Windows 8.1
Windows Rt 8.1
Windows Server 2012
Windows Server 2016
Windows Server 2019
Windows Server 2022
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2022-06-01
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 7.0
Version 8.0
Version 9.0
Configuration C
15 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
Version 1607
Version 1809
Version 20h2
Version 21h1
Version 21h2
All versions
All versions
All versions
Microsoft
All versions
Version r2
Microsoft
All versions
Version 20h2
All versions
All versions

References (6)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.