Cyber Security News

Microsoft Secure Boot Security 0-Day Lets Attackers Steal The Admin Credentials

A significant security vulnerability, identified as CVE-2023-24932, has been discovered in Microsoft’s Secure Boot feature.

This vulnerability allows attackers to bypass Secure Boot, potentially leading to the theft of admin credentials. The vulnerability was first disclosed on May 9, 2023, and has been updated as recently as February 11, 2025.

CVE-2023-24932 is classified as a Security Feature Bypass vulnerability with a CVSS score of 6.7 (Base) and 6.2 (Temporal).

The CVSS vector string is CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C.

This indicates that the vulnerability requires high privileges (PR:H) to exploit, meaning an attacker must have administrative rights or physical access to the device.

Researchers at Microsoft detected that to exploit this vulnerability, an attacker can install an affected boot policy, which could allow them to bypass Secure Boot protections.

Secure Boot is a critical security feature designed to ensure that only authorized firmware and operating systems can run on a device, preventing malicious code from executing during the boot process.

Impact and Mitigation

The vulnerability affects various versions of Windows, including Windows 11 and Windows Server 2022. Microsoft has released security updates to address this issue, but additional steps are required to fully mitigate the vulnerability.

For Windows 11 Version 23H2 and Windows Server 2022, 23H2 Edition, users must manually enable the protections.

In February 2025, Microsoft continued to address this vulnerability with additional updates.

Users are advised to install the latest security patches and follow the guidelines provided by Microsoft as to ensure their systems are protected, as the flaw has been already fixed at Feb update.

The CVE-2023-24932 vulnerability shows the importance of keeping systems updated and ensuring that security features like Secure Boot are properly configured.

Users should take proactive steps to enable the necessary protections and stay informed about the latest security updates to safeguard their devices against potential threats.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago