CVE-2023-24932

Published May 9, 2023

Last updated 2 years ago

Overview

Description
Secure Boot Security Feature Bypass Vulnerability
Source
secure@microsoft.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
6.7
Impact score
5.9
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-863

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

11

  1. Put together a full BPMN process diagram for the Secure Boot 2026 certificate deployment. Four lanes: Assessment, BIOS Updates, Phase 1 (certificate deployment), Phase 2 (revocation + SVN enforcement). This is what the complete CVE-2023-24932 remediation looks like end to end. h

    @kaidja

    22 Mar 2026

    1945 Impressions

    8 Retweets

    24 Likes

    20 Bookmarks

    0 Replies

    0 Quotes

  2. Just completed the full CVE-2023-24932 remediation on an enterprise Lenovo device. All four mitigations done. FirmwareSVN: 7.0. Compliant. Here is what most people do not know: the Intune Settings Catalog policy and Microsoft's 2026 Secure Boot playbook only cover mitigations ht

    @kaidja

    22 Mar 2026

    4611 Impressions

    18 Retweets

    57 Likes

    67 Bookmarks

    0 Replies

    0 Quotes

  3. 前に検証が中途半端になってたやつの検証終わったので、自動処理スクリプトもついでに公開 再起動を跨いで自律完走するセキュアブート(CVE-2023-24932)自動更新スクリプトの実装|はちくわ https://t.co/yBwh97vQu6

    @8chikuwa3

    4 Mar 2026

    507 Impressions

    2 Retweets

    6 Likes

    2 Bookmarks

    2 Replies

    0 Quotes

  4. Cybersecurity alert! Protect your system from the Black Lotus vulnerability (CVE-2023-24932) targeting Secure Boot. Here's what admins need to know to safeguard their devices. Don’t wait until it’s too late. Act now #CyberSecurity #InfoSec #CVE2023 https://t.co/29RYguGLBm

    @cheinyeanlim

    23 Mar 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Actively exploited CVE : CVE-2023-24932

    @transilienceai

    25 Feb 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Actively exploited CVE : CVE-2023-24932

    @transilienceai

    24 Feb 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Patch Tuesday and no update on the enforcement date for KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 Still waiting.. #Windows11 #Windows10 https://t.co/mrwQ3xlBYp

    @ccmexec

    14 Jan 2025

    2828 Impressions

    9 Retweets

    21 Likes

    6 Bookmarks

    2 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.