Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34302


A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.


Published

2022-08-26T18:15:09.047

Last Modified

2024-11-21T07:09:15.480

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System horizondatasys uefi_bootloader < 2022-06-01 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux 9.0 Yes
Operating System microsoft windows_10 - Yes
Operating System microsoft windows_10 20h2 Yes
Operating System microsoft windows_10 21h1 Yes
Operating System microsoft windows_10 21h2 Yes
Operating System microsoft windows_10 1607 Yes
Operating System microsoft windows_10 1809 Yes
Operating System microsoft windows_11 - Yes
Operating System microsoft windows_8.1 - Yes
Operating System microsoft windows_rt_8.1 - Yes
Operating System microsoft windows_server_2012 - Yes
Operating System microsoft windows_server_2012 r2 Yes
Operating System microsoft windows_server_2016 - Yes
Operating System microsoft windows_server_2016 20h2 Yes
Operating System microsoft windows_server_2019 - Yes
Operating System microsoft windows_server_2022 - Yes

References