CVE-2022-34301
published 2022-08-26CVE-2022-34301: A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections…
medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kidan | cryptopro_securedisk_for_bitlocker | < 2022-06-01 | 2022-06-01 |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2016 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
GHSA
GHSA-7j33-663j-fx7f: A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01
ghsa_unreviewed·2022-08-27
CVE-2022-34301 [MEDIUM] GHSA-7j33-663j-fx7f: A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Red Hat
shim: 3rd party shim allow secure boot bypass
vendor_redhat·2022-08-11·CVSS 6.7
CVE-2022-34301 [MEDIUM] CWE-494 shim: 3rd party shim allow secure boot bypass
shim: 3rd party shim allow secure boot bypass
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Statement: The shim packages distributed with Red Hat Enterprise Linux 7, 8 and 9 is not affected by this issue, however as the 3rd party affected shim is trusted by the UEFI platform an attacker can still use it to subvert secure boot protections in Red Hat Enterprise Linux installed systems. Red Hat is working to provide a DBX update v
Microsoft
CERT/CC: CVE-2022-34301 Eurosoft Boot Loader Bypass
vendor_msrc·2022-08-09·CVSS 6.7
CVE-2022-34301 [MEDIUM] CERT/CC: CVE-2022-34301 Eurosoft Boot Loader Bypass
CERT/CC: CVE-2022-34301 Eurosoft Boot Loader Bypass
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: Why are there different security update packages for this CVE?
These are standalone security updates. These packages must be installed in addition to the normal security updates to be protected from this vulnerability.
Are there any prerequisites to these security updates?
These security updates have a Servicing Stack Update prerequisite for specific KB numbers. The packages have a built in pre-requisite logic to ensure the ordering.
Customer should ensure that they have the latest Servicing Stack Update installed before installing these standalone se
No detection rules found.
No public exploits indexed.
Qualys
Introducing Qualys Threat Research Thursdays
blogs_qualys·2022-09-01
Introducing Qualys Threat Research Thursdays
## Table of Contents
Threat Intelligence from the Qualys Blog
New Threat Hunting Tools & Techniques
New Vulnerabilities
Introducing the Monthly Threat Thursdays Webinar
Welcome to the first edition of the Qualys Research Team’s “Threat Research Thursday” where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. We will endeavor to issue these update reports regularly, as often as every other week, or as our threat intelligence output warrants.
## Threat Intelligence from the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team from the past couple of weeks:
New Qualys Research Report: Evolution of Quasar RAT – This free downloadable report gives a sneak peek of the
Qualys
Introducing Qualys Threat Research Thursdays | Qualys
blogs_qualys·2022-09-01
Introducing Qualys Threat Research Thursdays | Qualys
#### Table of Contents
- Threat Intelligence from the Qualys Blog
- New Threat Hunting Tools & Techniques
- New Vulnerabilities
- Introducing the Monthly Threat Thursdays Webinar
Welcome to the first edition of the Qualys Research Team’s “Threat Research Thursday” where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. We will endeavor to issue these update reports regularly, as often as every other week, or as our threat intelligence output warrants.
## Threat Intelligence from the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team from the past couple of weeks:
- New Qualys Research Report: Evolution of Quasar RAT – This free downloadable report gives a sneak pee
Tenable
Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
blogs_tenable·2022-08-09·CVSS 7.8
[HIGH] Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Security Feature Bypass Vulnerabilities Addressed
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Evaluate Vendor-Suggested Workarounds With Policy Compliance
- Patch Tuesday is Complete.
- Qualys Monthly Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Security Feature Bypass Vulnerabilities Addressed
Microsoft Critical and Important Vulnerability Highlights
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Evaluate Vendor-Suggested Workarounds With Policy Compliance
Patch Tuesday is Complete.
Qualys Monthly Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Sum
https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boothttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.htmlhttps://www.kb.cert.org/vuls/id/309662https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boothttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.htmlhttps://www.kb.cert.org/vuls/id/309662
2022-08-26
Published