HomeSecuritySecure Boot flaw allows installation of bootkit malware

Secure Boot flaw allows bootkit malware to be installed

Security researchers have uncovered a new Secure Boot bypass flaw, which is listed as CVE-2025-3052 and can be used to disable security mechanisms on computers and servers, allowing the installation of bootkit-type malware.

See also: Honeywell: Ramnit malware infections are increasing

Secure Boot flaw

The flaw affects almost all systems that trust Microsoft's " UEFI CA 2011 " certificate , meaning essentially any hardware that supports Secure Boot.

Binarly researcher Alex Matrosovdiscovered the CVE-2025-3052 vulnerability when he spotted a BIOS update tool signed with Microsoft's UEFI signing certificate.

This particular tool was originally designed for rugged tablets, but because it was signed with Microsoft's UEFI certificate , it could be run on any system with Secure Boot enabled.

Further research revealed that this vulnerable module was distributed «freely» as early as the end of 2022 and later uploaded to VirusTotal in 2024, where it was detected by Binarly's team.

Binarly reported the Secure Boot flaw to CERT/CC on February 26, 2025, and CVE-2025-3052 is currently being addressed with the release of Microsoft's June 2025 Patch Tuesday security updates. However, during the assessment process, Microsoft found that the vulnerability affected 13 additional modules, which were added to the revocation database .

See also: Fake DocuSign pages distribute NetSupport RAT malware

bootkit malware

The vulnerability is caused by a legitimate BIOS update tool, signed with Microsoft’s “ UEFI CA 2011 ” certificate , which is trusted on most modern computers using UEFI firmware . This tool reads a user-writable NVRAM variable (IhisiParamBuffer), without checking it for validity. If an attacker has administrator privileges on the operating system, they can modify this variable to write arbitrary data to memory locations during UEFI boot — that is, before the operating system or even its kernel is loaded.

Exploiting this vulnerability, Binarly created a proof-of-concept exploit that zeroes out the 'gSecurity2' system variable, which is responsible for enforcing Secure Boot. Once Secure Boot is disabled, attackers can install bootkit-type malware, which can remain invisible to the operating system and disable additional security features.

To address the CVE-2025-3052 flaw, Microsoft has added the hashes of the affected modules to the Secure Boot dbx revocation list. Binarly and Microsoft urge users to immediately install the updated dbx file via today's security updates to protect devices .

See also: New self-propagating malware infects Docker Containers

An important point to make from the above is how even trusted, certified software, such as BIOS tools signed with valid Microsoft certificates, can pose a serious security risk when they contain vulnerabilities that are not detected in a timely manner. Therefore, it is essential for IT administrators and end users not to neglect firmware and Secure Boot updates, which are often overlooked in relation to operating system updates.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS