HomeinetNew PowerShell script fixes malicious bootkits in Windows

New PowerShell script fixes malicious bootkits in Windows

Microsoft has released a PowerShell script that makes it easier for Windows users and administrators to update their bootable media. The goal is to incorporate the new “ Windows UEFI CA 2023 ” certificate, before the restrictions related to the BlackLotus UEFI bootkit go into effect later this year.

See also: Malicious PowerShell scripts: What they are and how to protect yourself

PowerShell script

BlackLotus is an advanced UEFI bootkit that can bypass Secure Boot, gaining full control over the operating system boot process. Once installed, it has the ability to disable critical Windows security features such as BitLocker , Hypervisor-Protected Code Integrity (HVCI) , and Microsoft Defender Antivirus . This allows it to execute malware with the highest levels of privileges while maintaining its presence invisible.

In March 2023, and later in July 2024, Microsoft released security updates to address a secure boot vulnerability, known as CVE-2023-24932. These updates aimed to roll back vulnerable boot managers that had been exploited by the BlackLotus threat.

This patch remains disabled by default, as incorrect application or potential incompatibilities with devices could lead to problems loading the operating system. Rather than being enforced immediately, the gradual rollout of the fix gives administrators the opportunity to test it and evaluate its functionality before it becomes mandatory, which is expected to happen by 2026.

When the PowerShell script update is activated, the “Windows UEFI CA 2023” certificate will be added to the UEFI “Secure Boot Signature Database.” This allows administrators to install newer boot managers that are signed with this certificate.

See also: Variant of XWorm Delivered via Windows Script File

This process also includes updating the Database (DBX) to add the “Windows Production CA 2011” certificate. This certificate is used to sign older, vulnerable boot managers and once revoked, will cause these boot managers to become untrusted and fail to load.

New PowerShell script fixes malicious bootkits in Windows

However, if you apply the mitigations and experience a problem booting your devices, you must first update your bootable media to use the Windows UEFI CA 2023 certificate to troubleshoot Windows installation.

Yesterday, Microsoft released a PowerShell script that helps you update your bootable media to use the Windows UEFI CA 2023 certificate.

The PowerShell script can be downloaded from Microsoft and used to update bootable media files for CD/DVD ISO, a USB flash, a local drive path, or a network drive path.

To use the utility, you must first download and install the Windows ADK, which is required for this script to function properly. When executed, the script will update the media files to use the Windows UEFI CA 2023 certificate and install boot managers signed by this certificate.

See also: Phishing scam targets OneDrive users to execute malicious PowerShell script

A PowerShell script is a file that contains a series of commands and instructions written in the PowerShell scripting language. These scripts are used to automate various tasks, such as system administration, program execution, file management, or configuration. They usually have the extension “.ps1” and can be run in a Windows environment or other platforms that support PowerShell. PowerShell scripts are particularly useful for system administrators, as they offer great flexibility and the ability to automate complex processes.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS