CVE-2024-13745

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-13745 describes an issue within EDK II firmware where the measurement of bytes differs from those actually in use, specifically impacting the PCR measurements. These measurements are intended to record the expected GUID Partition Table (GPT) layout. Consequently, the trustworthiness of PCR measurements is compromised, as the system may appear "trusted" based on these measurements even if a malicious partition layout is being utilized. This discrepancy can affect systems relying on TPM-based Full Disk Encryption (FDE) and remote attestation, where the GPT layout is critical for security.

Description
-

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.