Windows 10: Microsoft may take up to a year to fix 0-day boot bug

Discus and support Microsoft may take up to a year to fix 0-day boot bug in Windows 10 News to solve the problem; Microsoft finds itself in a race against time as it tackles a significant and alarming 0-day secure boot bug that has sent shockwaves through the tech... Discussion in 'Windows 10 News' started by GHacks, May 12, 2023.

  1. GHacks
    GHacks New Member

    Microsoft may take up to a year to fix 0-day boot bug


    Microsoft finds itself in a race against time as it tackles a significant and alarming 0-day secure boot bug that has sent shockwaves through the tech community. This critical vulnerability, known as CVE-2023-24932, has resurfaced with another actively exploited workaround, affecting systems running Windows 10, Windows 11, and various Windows Server versions, dating all the way back to Windows Server 2008.

    With the potential to undermine the security of countless devices, Microsoft's response to this threat has become a top priority.

    Unmasking the BlackLotus Bootkit and CVE-2023-24932


    At the forefront of this security concern is the notorious BlackLotus bootkit. This real-world malware has gained infamy for its ability to bypass Secure Boot protections, granting hackers the ability to execute malicious code even before the Windows operating system and its essential security measures come into play.

    Secure Boot, enabled by default on numerous Windows PCs for over a decade, including popular brands like Dell, Lenovo, HP, and Acer, has been a fundamental line of defense. However, the emergence of BlackLotus has shattered the illusion of invulnerability.

    Microsoft may take up to a year to fix 0-day boot bug Windows-0-day-boot-bug.jpg
    Windows 0-day boot bug can be exploited in leading manufacturers
    The vulnerability exploited


    Microsoft warns that the 0-day secure boot bug can be exploited either through physical access to a system or by obtaining administrator rights. This makes the vulnerability a grave concern for both physical computers and virtual machines that have Secure Boot enabled. What sets this fix apart from other critical Windows updates is the decision to keep it disabled by default for several months after installation.

    This cautious approach aims to minimize any potential disruptions, as the update brings irreversible changes to the Windows boot manager, which may render existing Windows boot media unbootable.

    Navigating the patching journey ahead


    Microsoft has released a series of support articles emphasizing the importance of enabling the fix correctly to avoid system disruptions and startup failures. Once the fix is enabled, older bootable media lacking the necessary updates will no longer function on the system.

    This includes Windows installation media such as DVDs and USB drives created from Microsoft's ISO files, custom Windows install images maintained by IT departments, full system backups, network boot drives, stripped-down boot drives using Windows PE, and even recovery media bundled with OEM PCs.

    To ensure a smooth transition and minimize the risk of system failures, Microsoft has designed a phased approach for rolling out the update over the coming months. The initial patch release demands significant user involvement, requiring the installation of May's security updates and a meticulous five-step manual process involving the application and verification of "revocation files".

    These files update the system's hidden EFI boot partition and registry, establishing trust in the patched bootloader versions while revoking trust for older, vulnerable variants.

    Microsoft may take up to a year to fix 0-day boot bug Windows-0-day-boot-bug_2.jpg
    Microsoft has published multiple guides to minimize the effects of Windows 0-day boot bug
    Microsoft's streamlined fix update is coming in July


    Looking ahead, a second update is planned for July, streamlining the process of enabling the fix. The ultimate milestone is set for the first quarter of 2024 when the fix will be automatically enabled by default, rendering older boot media incompatible with all patched Windows systems. Microsoft acknowledges the possibility of accelerating this timeline, but the specifics remain unclear.

    Jean-Ian Boutin, ESET's director of threat research, has underscored the severity of the BlackLotus bootkit and similar threats, highlighting their ability to compromise secure boot mechanisms and gain control over the critical early phase of system startup.

    This latest fix sheds light on the ongoing challenges of addressing low-level Secure Boot and UEFI vulnerabilities. Recent incidents, such as the leakage of signing keys in a ransomware attack targeting computer and motherboard manufacturer MSI, further emphasize the complexity and importance of promptly addressing such issues.

    Thank you for being a Ghacks reader. The post Microsoft may take up to a year to fix 0-day boot bug appeared first on gHacks Technology News.

    read more...
     
    GHacks, May 12, 2023
    #1
  2. Ghot Win User

    Microsoft fixes 5 year old Windows Defender bug

    Microsoft fixes 5 year old Windows Defender bug that affected Firefox's performance

    gHacks article...

     
  3. jmcslob Win User
    2 x SSD Raid 0 - is this right?

    T ski b4 your done with this post can you list a step by step fix of what you did, I would appreciate it if you would...Thanks
     
    jmcslob, May 12, 2023
    #3
  4. Pinscher Win User

    Microsoft may take up to a year to fix 0-day boot bug

    Raid 0 help

    Hi all, I've followed the IRST raid installation directions and I have created myself a Raid 0 volume. Rapid storage confirms my successful migration from a system disc to a raid 0 array. I'm also able to select it as my boot device in BIOS, but what I don't understand is why it is not listed in my Drives under my computer

    In fact, my computer still lists my original C: drive with the original capacity. I feel as if I've miss an important step here and I'm unsure how to proceed.
     
    Pinscher, May 12, 2023
    #4
Thema:

Microsoft may take up to a year to fix 0-day boot bug

Loading...
  1. Microsoft may take up to a year to fix 0-day boot bug - Similar Threads - Microsoft may fix

  2. Fixing hard drive takes days

    in Windows 10 Gaming
    Fixing hard drive takes days: My laptop model is Lenovo L340 Old model Back when the Windows 11 was released 2021 I updated my laptop, and it stays 11 for about 1year or so 2022 .. before I decided to go back since i’m noticing some issues like: Slowness and inconsistency that I don’t think my laptop...
  3. Fixing hard drive takes days

    in Windows 10 Software and Apps
    Fixing hard drive takes days: My laptop model is Lenovo L340 Old model Back when the Windows 11 was released 2021 I updated my laptop, and it stays 11 for about 1year or so 2022 .. before I decided to go back since i’m noticing some issues like: Slowness and inconsistency that I don’t think my laptop...
  4. Fixing hard drive takes days

    in Windows 10 Customization
    Fixing hard drive takes days: My laptop model is Lenovo L340 Old model Back when the Windows 11 was released 2021 I updated my laptop, and it stays 11 for about 1year or so 2022 .. before I decided to go back since i’m noticing some issues like: Slowness and inconsistency that I don’t think my laptop...
  5. Fixing Disk Takes too long and still in 0%

    in Windows 10 Drivers and Hardware
    Fixing Disk Takes too long and still in 0%: Hey my laptop right now is in fixing disk state and it has been stuck in 0% for so long. It says "Fixing E: Stage 1 : 0%1087 of 612096; Total: 0%; ETA 999:00:00". Can anyone help me with the problem here? thanks...
  6. Fixing Disk Takes too long and still in 0%

    in Windows 10 Gaming
    Fixing Disk Takes too long and still in 0%: Hey my laptop right now is in fixing disk state and it has been stuck in 0% for so long. It says "Fixing E: Stage 1 : 0%1087 of 612096; Total: 0%; ETA 999:00:00". Can anyone help me with the problem here? thanks...
  7. Fixing Disk Takes too long and still in 0%

    in Windows 10 Software and Apps
    Fixing Disk Takes too long and still in 0%: Hey my laptop right now is in fixing disk state and it has been stuck in 0% for so long. It says "Fixing E: Stage 1 : 0%1087 of 612096; Total: 0%; ETA 999:00:00". Can anyone help me with the problem here? thanks...
  8. Bug that Microsoft Should Fix

    in AntiVirus, Firewalls and System Security
    Bug that Microsoft Should Fix: Dear communityThere is some thing Critically Problematic in Windows securityIf i Press then this Is what i get what is wrong with the windows security https://answers.microsoft.com/en-us/protect/forum/all/bug-that-microsoft-should-fix/1dda11cd-5ee3-4a26-815a-84088b9d6519
  9. Microsoft fixed a bug and made a bug.

    in Cortana
    Microsoft fixed a bug and made a bug.: The search glich again but even worse. https://answers.microsoft.com/en-us/windows/forum/all/microsoft-fixed-a-bug-and-made-a-bug/99b1930d-b293-4cd3-b64c-391bbbf3530e
  10. Microsoft Put Off Fixing Zero Day for 2 Years

    in Windows 10 Ask Insider
    Microsoft Put Off Fixing Zero Day for 2 Years: [ATTACH] submitted by /u/zanedow [link] [comments] https://www.reddit.com/r/Windows10/comments/ibfhw7/microsoft_put_off_fixing_zero_day_for_2_years/