blacklotus CVE-2022-21894

Anonymous
2023-08-09T00:13:41+00:00

What's the latest news on the Blacklotus vulnerability?as CVE-2022-21894

I'm becoming paranoid just booting up. The NSA has issued mitigation remedy but also issues a strongly worded caution.... Such as if you don't know what you're doing don't try it because it's difficult. It might be worth the trouble to take it to a professional to apply the NSA mitigation technique. I don't know!

This is for Windows 10 and Windows 11. I've included an article from bleeping computer that describes the issue in more detail. If anyone else has something give me a heads up please.

https://www.bleepingcomputer.com/news/security/blacklotus-bootkit-bypasses-uefi-secure-boot-on-patched-windows-11/

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2023-08-10T05:51:56+00:00

    Hello Satchul.

    Welcome to Microsoft Community.

    Regarding to your information I assume that you are worried about the Blacklotus CVE-2022-21894.

    According to this website said this vulnerability seems to have an official patch from the manufacturer.

    CVE-2022-21894 - Security Update Guide - Microsoft - Secure Boot Security Feature Bypass Vulnerability

    From the article posted on the Microsoft Security Blog, this attack needs remote administrative privileges on a target machine or physical

    access to the device.

    Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign | Microsoft Security Blog

    So for the personal user, if no people access your computer physically, you don't worry about an attack from the Black Lotus.

    Normally, if your Defender is up to date and functioning properly, you don't need to worry about this.

    If you really worry about it you can follow this article to make sure that your computer not be attacked by Black Lotus.

    • Recently written bootloader files
    • Staging directory artifacts created
    • Registry key modified
    • Windows Event logs entries generated
    • Network behavior
    • Boot Configuration log entries generated

    If there is anything not clear, please do not hesitate to let me know.

    Best Regards,

    Tommy-MSFT | Microsoft Community Support Specialist

    0 comments No comments