CVE-2024-8105

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.
Configurations

No configuration.

History

28 Jun 2026, 21:16

Type Values Removed Values Added
Summary (en) A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised. (en) A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

21 Nov 2024, 09:52

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/455367 -

09 Sep 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4

30 Aug 2024, 21:15

Type Values Removed Values Added
References
  • () https://kb.cert.org/vuls/id/455367 -
  • () https://www.binarly.io/advisories/brly-2024-005 -
  • () https://www.gigabyte.com/us/Support/Security/2205 -

27 Aug 2024, 13:02

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto una vulnerabilidad relacionada con el uso de una clave de plataforma (PK) insegura. Un atacante con la clave privada PK comprometida puede crear software UEFI malicioso firmado con una clave confiable que ha sido comprometida.

26 Aug 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-26 20:15

Updated : 2026-06-28 21:16


NVD link : CVE-2024-8105

Mitre link : CVE-2024-8105

CVE.ORG link : CVE-2024-8105


JSON object : View

Products Affected

No product.

CWE

No CWE.