CVE-2024-7344: Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Description

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Classification

CVE ID: CVE-2024-7344

Affected Products

Vendor: Radix

Product: SmartRecovery

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 0.29% (scored less or equal to compared to others)

EPSS Date: 2025-02-12 (when was this score calculated)

References

https://uefi.org/revocationlistfile
https://uefi.org/specs/UEFI/2.10/32_Secure_Boot_and_Driver_Signing.html
https://uefi.org/specs/UEFI/2.10/03_Boot_Manager.html
https://www.eset.com/blog/enterprise/preparing-for-uefi-bootkits-eset-discovery-shows-the-importance-of-cyber-intelligence/

Timeline