MidnightBSD

Advisories for kidan

CVE-2022-34301

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.7 MEDIUM CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 0.8 5.9

Products Affected

Vendor Product Version
redhat enterprise_linux 9.0
microsoft windows_server_2012 r2
microsoft windows_server_2022 -
microsoft windows_11 -
microsoft windows_server_2016 20h2
microsoft windows_10 -
microsoft windows_10 21h2
redhat enterprise_linux 8.0
microsoft windows_10 21h1
redhat enterprise_linux 7.0
microsoft windows_rt_8.1 -
microsoft windows_server_2016 -
microsoft windows_10 1607
microsoft windows_server_2019 -
microsoft windows_10 20h2
microsoft windows_10 1809
microsoft windows_server_2012 -
kidan cryptopro_securedisk_for_bitlocker *
microsoft windows_8.1 -