GPU VulnDB

Database/Firmware, BMC & network fabric

Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wild

CVE-2023-24932Firmware, BMC & network fabricBlackLotuscurated

Impact

The bypass the BlackLotus UEFI bootkit used in the wild. An attacker with admin or physical access installs a bootkit that survives OS reinstall and disk replacement, disables Secure Boot enforcement from inside the boot chain, and hides from every in-OS security agent. On a mixed Windows/Linux estate this also poisons attestation for anything downstream.

Who can reach it

Local administrator or physical access - which on bare metal means any tenant that rented the node, and on a colo floor means anyone with remote-hands.

What to do

The most operationally painful entry in this cluster. The security update alone does nothing: Microsoft shipped it behind a manual, multi-stage opt-in requiring boot manager updates, revocation of the old boot manager, and a UEFI CA/dbx update, staged over roughly two years precisely because enabling revocation early bricks machines that still boot old media. Budget for a phased rollout with per-node verification, keep known-good recovery media that is still trusted, and expect to touch firmware settings on some boards. Not a patch-and-forget.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.