CVE-2023-24932Patch(microsoft / windows_10_1507)

HIGHCVSS 6.7 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Secure Boot Security Feature Bypass Vulnerability

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_20h2

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-06-16); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_20h2windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_server_2008windows_server_2012

2 versions affected across 13 products

Deep dive

Activity timeline11 mentions / 8d
01223Mentions · 2026-02-24: 1Mentions · 2026-02-26: 1Mentions · 2026-03-04: 1Mentions · 2026-03-22: 2Mentions · 2026-06-16: 3Mentions · 2026-06-29: 1Mentions · 2026-08-11: 1Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-06-29: 1Active Exploitation · 2026-06-16: 2Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-03-22: 1Technical Details · 2026-06-16: 102-2402-2603-0403-2206-1606-2908-1108-30
Signal classification4 categories
Patch
654.5%
General
218.2%
Active Exploitation
218.2%
PoC
19.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-241
Patch1
2026-02-261
Patch1
2026-03-041
Patch1
2026-03-222
General1Patch1
2026-06-163
Active Exploitation2Patch1
2026-06-291
PoC1
2026-08-111
General1
2026-08-301
Patch1
Full discourse11 posts
  • Kaido Järvemets@kaidja
    Patch

    Just completed the full CVE-2023-24932 remediation on an enterprise Lenovo device. All four mitigations done. FirmwareSVN: 7.0. Compliant. Here is what most people do not know: the Intune Settings Catalog policy and Microsoft's 2026 Secure Boot playbook only cover mitigations 1-2 (certificate deployment). Mitigations 3-4 (2011 CA revocation and SVN enforcement) are a separate step that is not documented in any of the 2026 guidance. The cmdlet to verify it (Get-SecureBootSVN) was quietly added in KB5077241 with two sentences in the changelog. Your device can show Event 1808, UEFICA2023Status Updated, Capable 2, and still be SVN non-compliant. I am running a Secure Boot workshop on April 8. If you want to understand the full picture and not just what the playbook tells you, join me there. Register here: https://docs.kaidojarvemets.com/training/secure-boot-workshop

    Post summary

    The author has fully remediated CVE‑2023‑24932 on a Lenovo device, highlighting that four mitigations exist, two of which are not covered in standard guidance, and invites a workshop to discuss the complete mitigation picture.

    019066826.0K
    4.0K followersView on X
  • SystemCenterDudes@scdudes
    General

    The June 2026 Secure Boot cert expiration is only step 1. Neutralizing the BlackLotus bootkit (CVE-2023-24932) takes 4 ordered mitigations. Our deep dive + free Power BI dashboard help you track every device through the process: https://www.systemcenterdudes.com/blacklotus-remediation-beyond-the-ca-certificate-expiration/ #MSIntune #BlackLotus https://t.co/BdN8LZJGFA

    Post summary

    The post highlights a resource for mitigating CVE‑2023‑24932 but lacks detailed technical, exploit or patch information.

    117064414.4K
    10.1K followersView on X
  • Kaido Järvemets@kaidja
    General

    Put together a full BPMN process diagram for the Secure Boot 2026 certificate deployment. Four lanes: Assessment, BIOS Updates, Phase 1 (certificate deployment), Phase 2 (revocation + SVN enforcement). This is what the complete CVE-2023-24932 remediation looks like end to end. See you on April 8th! Register here: https://docs.kaidojarvemets.com/training/secure-boot-workshop #SecureBoot #BPMN #UEFI #CVE202324932 #Windows

    Post summary

    The post appears to be a promotional announcement for a training workshop covering the remediation process for CVE‑2023‑24932, without any technical or exploit‑related details.

    08026252.3K
    4.0K followersView on X
  • SystemCenterDudes@scdudes
    Patch

    This post explains what is really happening under CVE-2023-24932 (BlackLotus vulnerability), the 4 mitigations and how to apply them manually with #PowerShell, and much more - https://www.systemcenterdudes.com/blacklotus-remediation-beyond-the-ca-certificate-expiration/ #CyberSecurity #BlackLotus #MSIntune https://t.co/LTEFqEIFnl

    Post summary

    The tweet links to a post that explains how to mitigate CVE‑2023‑24932 (BlackLotus) by applying four manual PowerShell-based mitigations.

    09017203.1K
    10.0K followersView on X
  • 咲内ひなた@SakunaiHinata
    PoC

    この台湾巴哈姆特製作のセキュアブート証明書チェックツール入手する為には↓ ① https://github.com/SimonMacer/CreateMediaRefresh25H2/releases/tag/SBTUpdate にアクセスし、1番下の「http://CVE-2023-24932.zip」をダウンロード ②zip書庫内の「CVE-2023-24932」フォルダを丸ごと展開させ ③「1.CheckEFIBootFileUpdated.cmd」を右クリックし「管理者として実行」 安全の為、他の「2~6」のcmdを実行しないでください ④結果が見れる

    Post summary

    The post supplies a GitHub link to a zip archive containing code (a script) that checks for the CVE‑2023‑24932 secure‑boot certificate verification, but it does not present an exploit, patch, or evidence of active exploitation.

    2101051.3K
    12.8K followersView on X
  • はちくわ@8chikuwa3
    Patch

    前に検証が中途半端になってたやつの検証終わったので、自動処理スクリプトもついでに公開 再起動を跨いで自律完走するセキュアブート(CVE-2023-24932)自動更新スクリプトの実装|はちくわ https://zenn.dev/8chikuwa3/articles/271b18d38820b2 #zenn

    Post summary

    A user publishes an automatic update script that patches CVE‑2023‑24932 (Secure Boot), providing a workaround via the linked article.

    22062651
    2.3K followersView on X
  • Imran Awan@imran76awan
    Patch

    BlackLotus Mitigation and Secure Boot Certificate Lifecycle Management https://youtu.be/ypOwxY7e0_4?is=w7fjIddQZ1AxtUcl via @YouTube Y our Secure Boot report shows the 2023 certificate installed and calls it done - but CVE-2023-24932 (BlackLotus) needs four separate mitigation #intune #secureboot #tpm

    Post summary

    YouTube video discusses BlackLotus CVE-2023-24932 and notes that four separate mitigations are required, but offers no exploit details or evidence of active exploitation.

    00020379
    753 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    China-linked FishMonger deployed Windows variants of the SprySOCKS backdoor in four countries including Honduras and Taiwan in 2023-2024, with telemetry indicating a UEFI bootkit linked to CVE-2023-24932, ESET reported. https://threatcluster.io/cluster/new-windows-variants-of-sprysocks-malware-target-government--f27532dc

    Post summary

    ESET reports that China‑linked FishMonger deployed Windows variants of the SprySOCKS backdoor across multiple countries, with telemetry indicating exploitation via a UEFI bootkit tied to CVE‑2023‑24932.

    00020326
    441 followersView on X
  • Johan Arwidmark@jarwidmark
    Patch

    @alkhacnar @gwblok has a task sequence you can copy actions from but I have only tested that as a standalone TS: https://garytown.com/configmgr-task-sequence-kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932

    Post summary

    The tweet points to a task sequence that serves as a workaround for CVE-2023-24932, without providing exploit code or evidence of active exploitation.

    00011111
    23.2K followersView on X
  • アーモンドグリーン@a1mondgreen_
    Patch

    インストールメディア側の証明書の更新方法は後述のリンク先にあり、全体の流れとしては下記。 1) PC側のセキュアブート証明書を更新 2) インストールメディアをUSBメモリ上に作成 3) 1)を済ませたPC上で下記のリンク先に書かれたコマンドを実行(ドライブ名に要注意) https://support.microsoft.com/ja-jp/topic/cve-2023-24932-%E3%81%AB%E9%96%A2%E9%80%A3%E4%BB%98%E3%81%91%E3%82%89%E3%82%8C%E3%81%A6%E3%81%84%E3%82%8B%E3%82%BB%E3%82%AD%E3%83%A5%E3%82%A2-%E3%83%96%E3%83%BC%E3%83%88%E3%81%AE%E5%A4%89%E6%9B%B4%E3%81%AB%E5%AF%BE%E3%81%99%E3%82%8B-windows-%E3%83%96%E3%83%BC%E3%83%88-%E3%83%9E%E3%83%8D%E3%83%BC%E3%82%B8%E3%83%A3%E3%83%BC%E5%A4%B1%E5%8A%B9%E3%82%92%E7%AE%A1%E7%90%86%E3%81%99%E3%82%8B%E6%96%B9%E6%B3%95-41a975df-beb2-40c1-99a3-b3ff139f832d#bkmk_windows_install_media

    Post summary

    The post offers a step‑by‑step workaround for CVE‑2023‑24932 by updating the installation media certificate, citing a Microsoft support article for guidance.

    10010239
    15 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    ESET found Windows SprySOCKS backdoor variants used against government orgs in Taiwan, Thailand, Pakistan, and Honduras, with high-confidence attribution to Earth Lusca and possible ties to CVE-2023-24932. #Taiwan #EarthLusca #SprySOCKS https://ift.tt/XIbVTfS

    Post summary

    ESET reports that SprySOCKS backdoor variants have been actively exploited against government organizations in several countries, attributing attacks to Earth Lusca and noting a possible link to CVE-2023-24932.

    00000153
    4.4K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more