Database/Control plane, storage & DevOps

Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkit
CVSS 4.4CVE-2022-21894Control plane, storage & DevOpsBlackLotuscurated
Impact
Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkit; the bootkit survives OS reinstall and disk replacement because it lives in the ESP with a revoked-but-still-trusted bootloader
Who can reach it
Local, high privilege
What to do
dbx revocation and the phased Microsoft boot-manager revocation rollout. Low CVSS badly understates it: the score reflects the local-privilege precondition, not the below-OS persistence that follows
References
Related entries
- Redis: Malformed ACL selector triggers a server panicCVE-2024-51741 · RedisMedium
- GitLab EE: Owner or Maintainer can silently disable protected-environment deployment approvalsCVE-2026-86341 · GitLab EE (protected environment deployment approval rules)Medium
- Grafana: A user can block another user's login by registering their email address as a usernameCVE-2022-39229 · GrafanaMedium
- Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access andCVE-2023-31042 · Pure Storage FlashBlade object store protocolMedium
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationCVE-2023-31203 · OpenVINO Model ServerMedium
- GitLab: crafted Git ref names make the web UI show different content than the downloaded archiveCVE-2025-12506 · GitLab CE/EE (Git reference name resolution)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.