Database/Firmware, BMC & network fabric

Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery application
Impact
A Microsoft-signed UEFI recovery application loads an unsigned binary from a hardcoded path using its own loader instead of the firmware's verified LoadImage. Anyone holding a copy of that signed application can drop it on any Secure Boot machine that trusts the Microsoft third-party CA and boot arbitrary pre-OS code - the vulnerable system does not need the vendor's product installed. That is a universal, portable Secure Boot bypass usable to plant a bootkit on a rented GPU node.
Who can reach it
Write access to the EFI System Partition - local admin/root, prior bare-metal tenant, or BMC virtual media. No relationship to whether you use the affected recovery software.
What to do
Apply the January 2025 UEFI revocation list (dbx) update that revokes the affected binaries - this is a firmware-level revocation, not a package update, so it lands via Windows Update, fwupd/LVFS, or an OEM BIOS update depending on the platform. Verify the revocation actually took on each node; dbx pushes silently no-op on some boards. Also audit the ESP for stray signed EFI applications you never installed.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.