Database/Control plane, storage & DevOps

Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkit
CVE-2022-21894Control plane, storage & DevOpsBlackLotuscurated
Impact
Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkit; the bootkit survives OS reinstall and disk replacement because it lives in the ESP with a revoked-but-still-trusted bootloader
Who can reach it
Local, high privilege
What to do
dbx revocation and the phased Microsoft boot-manager revocation rollout. Low CVSS badly understates it: the score reflects the local-privilege precondition, not the below-OS persistence that follows
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.