2025-09-29 16:08:36 +00:00
|
|
|
### [CVE-2024-7344](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7344)
|
|
|
|
|

|
|
|
|
|

|
|
|
|
|

|
|
|
|
|

|
|
|
|
|

|
|
|
|
|
&color=blue)
|
2025-09-29 21:09:30 +02:00
|
|
|

|
|
|
|
|

|
|
|
|
|

|
2025-09-29 16:08:36 +00:00
|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
|
|
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
|
|
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
|
|
#### Reference
|
2025-09-29 21:09:30 +02:00
|
|
|
- https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html
|
|
|
|
|
- https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/
|
2025-09-29 16:08:36 +00:00
|
|
|
|
|
|
|
|
#### Github
|
2025-09-29 21:09:30 +02:00
|
|
|
- https://github.com/0xAtef/0xAtef
|
|
|
|
|
- https://github.com/DevGreick/devgreick
|
|
|
|
|
- https://github.com/felipealfonsog/felipealfonsog
|
2025-09-29 16:08:36 +00:00
|
|
|
- https://github.com/francolop/0XC0DE-TP3
|
2025-09-29 21:09:30 +02:00
|
|
|
- https://github.com/frlc/frlc
|
2025-09-29 16:08:36 +00:00
|
|
|
|