View Single Post
  #2  
Old July 30th 20, 07:00 AM posted to alt.comp.os.windows-8,alt.comp.os.windows-10,alt.os.linux
Andrei Z.
external usenet poster
 
Posts: 6
Default BootHole Secure Boot Threat Found In Most Every Linux Distro,Windows 8 And 10

Arlen Holder wrote:
Dateline today, verbatim...
"Security researchers at Eclypsium discovered a vulnerability that
affects the bootloader used by 'virtually every' Linux system,
and almost every Windows device using Secure Boot with Microsoft's
standard Unified Extensible Firmware Interface (UEFI) certificate
authority."

o *BootHole Secure Boot Threat Found In Most Every Linux Distro, Windows 8 And 10*
https://www.forbes.com/sites/daveywinder/2020/07/29/boothole-secure-boot-threat-confirmed-in-most-every-linux-distro-windows-8-and-10-microsoft-ubuntu-redhat-suse-debian-citrix-oracle-vmware/

"CVE-2020-10713, dubbed BootHole, has a high CVSS rating of 8.2
and sits in the default GRand Unified Bootloader 2 (GRUB2)
but affects systems running Secure Boot even if they are not
using GRUB2.

If successfully exploited, BootHole opens up Windows and Linux devices
to arbitrary code execution during the boot process, even when Secure
Boot is enabled. Meaning an attacker could gain persistence for
stealthily installed malware and give them, "near-total control"
over the device, according to Eclypsium."


"multiple secure boot grub2 and linux kernel vulnerabilities" - oss-security
https://www.openwall.com/lists/oss-s...y/2020/07/29/3

"Mitigating BootHole ..." - Ubuntu
https://ubuntu.com//blog/mitigating-...ulnerabilities
Ads