Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-0689

Опубликовано: 12 фев. 2020
Источник: msrc
CVSS3: 8.2
EPSS Низкий

Описание

Microsoft Secure Boot Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in secure boot. An attacker who successfully exploited the vulnerability can bypass secure boot and load untrusted software.

To exploit the vulnerability, an attacker could run a specially crafted application.

The security update addresses the vulnerability by blocking vulnerable third-party bootloaders.

For further information see Security update for Secure Boot DBX: January 12, 2021.

FAQ

Why are there different security update packages for this CVE?

These are standalone security updates. These packages must be installed in addition to the normal security updates to be protected from this vulnerability.

Are there any prerequisites to these security updates?

These security updates have a Servicing Stack Update prerequisite for specific KB numbers. The packages have a built in pre-requisite logic to ensure the ordering.

Customer should ensure that they have the following Servicing Stack Update installed before installing these standalone security updates:

ProductSSU PackageDate Released
Windows Server 20124566426July 2020
Windows 8.1/Server 2012 R24524445July 2020
Windows 104565911July 2020
Windows 10 Version 1607/Server 20164576750September 2020
Windows 10 1803/Windows Server, version 18034580398October 2020
Windows 10 1809/Server 20194598480January 2021
Windows 10 1909/Windows Server, version 19094598479January 2021

If I need to manually install these standalone updates, a Servicing Stack Update, and a January 2021 Security Update, in what order should they be installed?

Customers who need to manually install these three updates should install them in the following order:

  • Servicing Stack Update
  • Standalone Secure Boot Update listed in this CVE
  • January 2021 Security Update

Customers whose systems are configured to receive automatic updates will automatically receive these updates in the correct order.

Is there anything else that I should know about these updates?

If Windows Defender Credential Guard (Virtual Secure Mode) is enabled, two additional reboots will be required.

Why have the x86 and ARM64 versions of Windows been removed from the Security Updates table?

The x86 and ARM64 versions of Windows have been removed because these architectures are not affected by this vulnerability.

Обновления

ПродуктСтатьяОбновление
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows 8.1 for x64-based systems
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows 10 for x64-based Systems
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows Server 2016 (Server Core installation)
Windows 10 Version 1803 for x64-based Systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 62%
0.01039
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
больше 6 лет назад

A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.

github
больше 4 лет назад

A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.

CVSS3: 6.7
fstec
больше 6 лет назад

Уязвимость реализации протокола безопасной загрузки Secure Boot операционных систем Windows, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 62%
0.01039
Низкий

8.2 High

CVSS3