GPU VulnDB

Database/Firmware, BMC & network fabric

CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitrary

CVE-2022-34301Firmware, BMC & network fabricThree more bootloaderscurated

Impact

A Microsoft-signed bootloader that can be made to execute arbitrary pre-boot code. Same portable-bypass shape as the Howyar case: the attacker brings the signed binary with them, so a fleet that never deployed this product is still exploitable simply because the firmware trusts the signature.

Who can reach it

Write access to the EFI System Partition on the target node.

What to do

dbx revocation update pushed to every node via firmware update or OS vendor channel - not a package upgrade. Verify the dbx entry is present afterwards; revocation is the only fix because the vulnerable binary is signed and portable.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.