Cyber Posture

CVE-2024-7344

HighPublic PoC

Published: 14 January 2025

Published
14 January 2025
Modified
22 January 2025
KEV Added
Patch
CVSS Score 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0039 59.7th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Security Summary

CVE-2024-7344 is a vulnerability in the Howyar UEFI Application "Reloader," affecting both 32-bit and 64-bit versions. It enables the execution of unsigned software stored in a hardcoded path, linked to CWE-347 (Improper Verification of Signature). The issue carries a CVSS v3.1 base score of 8.2 (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) and was published on 2025-01-14.

A local attacker with high privileges can exploit this vulnerability with low complexity and no user interaction required. Exploitation allows execution of unsigned code in the specified path, potentially compromising confidentiality, integrity, and availability at a high level within a changed scope, such as during the UEFI boot process.

Advisories and references, including the CERT vulnerability note (https://www.kb.cert.org/vuls/id/529659), UEFI specifications on the Boot Manager (https://uefi.org/specs/UEFI/2.10/03_Boot_Manager.html) and Secure Boot and Driver Signing (https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html), and the UEFI revocation list file (https://uefi.org/revocationlistfile), provide context on Secure Boot mechanisms and signature verification. An ESET blog post (https://www.eset.com/blog/enterprise/preparing-for-uefi-bootkits-eset-discovery-shows-the-importance-of-cyber-intelligence/) discusses UEFI bootkit preparations and the role of cyber intelligence.

Details

CWE(s)
CWE-347

Affected Products

cs-grp
neo impact
≤ 10.1.024-20241127
greenware
greenguard
≤ 10.2.023-20240927
howyar
sysreturn
≤ 10.2.023_20240919
radix
smart recovery
≤ 11.2.023-20240927
sanfong
ez-back system
≤ 10.3.024-20241127
signalcomputer
hdd king
≤ 10.3.021-20241127
wasay
erecoveryrx
≤ 8.4.022-20241127

References