CVE-2022-34301 - CVE House
Back to Database
Status published Medium CVE-2022-34301

A flaw was found in CryptoPro Secure Disk bootloaders before...

Vulnerability Description

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-34301

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cryptopro securedisk for bitlocker, enterprise linux, windows 10, windows 11, windows 8.1, windows rt 8.1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Vulnerable Versions:
0, 7.0, 8.0, 9.0, 20h2, 21h1, 21h2, 1607, 1809, r2

Timeline

Official Publish: August 26th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.