VDB
BDU%3A2025-00366
BDU%3A2025-00366
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость UEFI-загрузчика Howyar Reloader операционных систем Windows, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Howyar Technologies | Windows Server 2012, Windows Server 2012 R2, Windows 10, Windows 10 1607, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 21H2, Windows 11 22H2, Windows 10 22H2, Windows Server 2012 (Server Core installation), Windows 11 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 24H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Howyar Reloader |
Timeline
- Jan 16, 2025 CVE Published
- Sep 26, 2025 CVE Updated
- Mar 20, 2026 Security Advisory
- Mar 20, 2026 Security Advisory
References
- https://uefi.org/revocationlistfile url
- https://uefi.org/specs/UEFI/2.10/03_Boot_Manager.html url
- https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html url
- https://www.eset.com/blog/enterprise/preparing-for-uefi-bootkits-eset-discovery-shows-the-importance-of-cyber-intelligence/ url
- https://www.kb.cert.org/vuls/id/529659 url
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-7344 url
- https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/ url
- https://www.welivesecurity.com/en/eset-research/introducing-hybridpetya-petya-notpetya-copycat-uefi-secure-boot-bypass/ url