Описание
Microsoft Secure Boot Security Feature Bypass Vulnerability
A security feature bypass vulnerability exists in secure boot. An attacker who successfully exploited the vulnerability can bypass secure boot and load untrusted software.
To exploit the vulnerability, an attacker could run a specially crafted application.
The security update addresses the vulnerability by blocking vulnerable third-party bootloaders.
For further information see Security update for Secure Boot DBX: January 12, 2021.
FAQ
Why are there different security update packages for this CVE?
These are standalone security updates. These packages must be installed in addition to the normal security updates to be protected from this vulnerability.
Are there any prerequisites to these security updates?
These security updates have a Servicing Stack Update prerequisite for specific KB numbers. The packages have a built in pre-requisite logic to ensure the ordering.
Customer should ensure that they have the following Servicing Stack Update installed before installing these standalone security updates:
| Product | SSU Package | Date Released |
|---|---|---|
| Windows Server 2012 | 4566426 | July 2020 |
| Windows 8.1/Server 2012 R2 | 4524445 | July 2020 |
| Windows 10 | 4565911 | July 2020 |
| Windows 10 Version 1607/Server 2016 | 4576750 | September 2020 |
| Windows 10 1803/Windows Server, version 1803 | 4580398 | October 2020 |
| Windows 10 1809/Server 2019 | 4598480 | January 2021 |
| Windows 10 1909/Windows Server, version 1909 | 4598479 | January 2021 |
If I need to manually install these standalone updates, a Servicing Stack Update, and a January 2021 Security Update, in what order should they be installed?
Customers who need to manually install these three updates should install them in the following order:
- Servicing Stack Update
- Standalone Secure Boot Update listed in this CVE
- January 2021 Security Update
Customers whose systems are configured to receive automatic updates will automatically receive these updates in the correct order.
Is there anything else that I should know about these updates?
If Windows Defender Credential Guard (Virtual Secure Mode) is enabled, two additional reboots will be required.
Why have the x86 and ARM64 versions of Windows been removed from the Security Updates table?
The x86 and ARM64 versions of Windows have been removed because these architectures are not affected by this vulnerability.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Windows Server 2012 | ||
| Windows Server 2012 (Server Core installation) | ||
| Windows 8.1 for x64-based systems | ||
| Windows Server 2012 R2 | ||
| Windows Server 2012 R2 (Server Core installation) | ||
| Windows 10 for x64-based Systems | ||
| Windows Server 2016 | ||
| Windows 10 Version 1607 for x64-based Systems | ||
| Windows Server 2016 (Server Core installation) | ||
| Windows 10 Version 1803 for x64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
8.2 High
CVSS3
Связанные уязвимости
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
Уязвимость реализации протокола безопасной загрузки Secure Boot операционных систем Windows, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
8.2 High
CVSS3