跳转到帖子

Microsoft Windows: CVE-2023-40547: Redhat: CVE-2023-40547 Shim - RCE in HTTP boot support may lead to secure boot bypass

recommended_posts

发布于
  • Members

Microsoft Windows: CVE-2023-40547: Redhat: CVE-2023-40547 Shim - RCE in HTTP boot support may lead to secure boot bypass

Severity
8
CVSS
(AV:A/AC:M/Au:N/C:C/I:C/A:C)
Published
08/13/2024
Created
08/14/2024
Added
08/13/2024
Modified
09/11/2024

Description

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

Solution(s)

  • microsoft-windows-windows_10-1507-kb5041782
  • microsoft-windows-windows_10-1607-kb5041773
  • microsoft-windows-windows_10-1809-kb5041578
  • microsoft-windows-windows_10-21h2-kb5041580
  • microsoft-windows-windows_10-22h2-kb5041580
  • microsoft-windows-windows_11-21h2-kb5041592
  • microsoft-windows-windows_11-22h2-kb5041585
  • microsoft-windows-windows_11-23h2-kb5041585
  • microsoft-windows-windows_11-24h2-kb5041571
  • microsoft-windows-windows_server_2012-kb5041851
  • microsoft-windows-windows_server_2012_r2-kb5041828
  • microsoft-windows-windows_server_2016-1607-kb5041773
  • microsoft-windows-windows_server_2019-1809-kb5041578
  • microsoft-windows-windows_server_2022-21h2-kb5041160
  • microsoft-windows-windows_server_2022-22h2-kb5041160
  • microsoft-windows-windows_server_2022-23h2-kb5041573

References

  • https://attackerkb.com/topics/cve-2023-40547
  • CVE - 2023-40547
  • https://support.microsoft.com/help/5041160
  • https://support.microsoft.com/help/5041571
  • https://support.microsoft.com/help/5041573
  • https://support.microsoft.com/help/5041578
  • https://support.microsoft.com/help/5041580
  • https://support.microsoft.com/help/5041585
  • https://support.microsoft.com/help/5041592
  • https://support.microsoft.com/help/5041773
  • https://support.microsoft.com/help/5041782
  • https://support.microsoft.com/help/5041828
  • https://support.microsoft.com/help/5041851
View more
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…