Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-37970

CVE-2024-37970: Windows 10 1507 Auth Bypass Vulnerability

CVE-2024-37970 is a Secure Boot authentication bypass vulnerability in Microsoft Windows 10 1507 that undermines security protections. This article covers technical details, affected versions, security impact, and mitigation.

Published:

CVE-2024-37970 Overview

CVE-2024-37970 is a Secure Boot security feature bypass vulnerability affecting a broad range of Microsoft Windows client and server operating systems. The flaw allows an attacker on an adjacent network to bypass Secure Boot integrity checks after convincing a user to perform an action, undermining a foundational platform trust boundary. Microsoft published the advisory on July 9, 2024, and classifies it as [CWE-121] stack-based buffer overflow. Successful exploitation compromises confidentiality, integrity, and availability of the affected host. The vulnerability impacts Windows 10, Windows 11, and Windows Server editions from 2012 through 2022 23H2.

Critical Impact

Attackers who bypass Secure Boot can load unsigned or malicious bootloaders, enabling pre-OS persistence and evasion of standard endpoint controls.

Affected Products

  • Microsoft Windows 10 (1507, 1607, 1809, 21H2, 22H2)
  • Microsoft Windows 11 (21H2, 22H2, 23H2)
  • Microsoft Windows Server 2012, 2016, 2019, 2022, and 2022 23H2

Discovery Timeline

  • 2024-07-09 - CVE-2024-37970 published to the National Vulnerability Database
  • 2024-07-09 - Microsoft releases the CVE-2024-37970 Update Guide
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-37970

Vulnerability Analysis

CVE-2024-37970 is a stack-based buffer overflow ([CWE-121]) in Windows components that participate in the Secure Boot trust chain. Secure Boot validates firmware and bootloader signatures before handing execution to the operating system loader. A bypass in this component allows unsigned or tampered code to execute during boot, defeating a key defense against bootkits and firmware-resident malware.

The flaw requires user interaction and an adjacent network position, per the CVSS vector. This attack model aligns with scenarios where an attacker on the same local network segment delivers a crafted payload processed during early boot or update flows. Once Secure Boot is bypassed, adversaries can persist below the operating system, where traditional file-based scanners have limited visibility.

Root Cause

The root cause is improper bounds checking in a Secure Boot code path, producing a stack-based buffer overflow. Overwriting adjacent stack memory allows attacker-controlled data to influence control flow during a component that Windows treats as trusted. Because the affected code runs before or alongside Secure Boot validation, memory corruption here can invalidate the platform's chain of trust.

Attack Vector

Exploitation requires an adjacent network attack vector and user interaction. The attacker must be positioned on the same broadcast domain or adjacent logical network segment as the target and induce the user to trigger the vulnerable code path. No privileges are required prior to the interaction. No public proof-of-concept exploit or CISA KEV listing has been recorded. The EPSS probability is 1.056% as of the latest scoring cycle.

No verified exploit code is available. See the Microsoft CVE-2024-37970 Update Guide for vendor technical detail.

Detection Methods for CVE-2024-37970

Indicators of Compromise

  • Unexpected changes to Secure Boot policy, dbx revocation list, or UEFI variables on managed endpoints.
  • Boot Configuration Data (BCD) modifications, unsigned bootloaders, or unknown entries in the EFI System Partition.
  • Measured Boot logs (TPM PCR values) diverging from a known-good baseline after routine reboots.
  • Windows Event Log entries indicating Secure Boot verification failures or driver signature enforcement warnings.

Detection Strategies

  • Compare TPM attestation results against golden baselines using device health attestation services.
  • Hunt for writes to \EFI\Microsoft\Boot\ and \EFI\Boot\ paths by non-system processes.
  • Correlate adjacent-network anomalies (rogue DHCP, PXE, or WSUS traffic) with unexpected reboots.

Monitoring Recommendations

  • Enable and forward Microsoft-Windows-CodeIntegrity operational logs to a centralized data lake.
  • Monitor for firmware and Secure Boot revocation list updates delivered outside the standard patch window.
  • Alert on bcdedit invocations that disable Secure Boot, integrity checks, or test signing.

How to Mitigate CVE-2024-37970

Immediate Actions Required

  • Apply the July 2024 Microsoft security updates that address CVE-2024-37970 to all affected Windows 10, Windows 11, and Windows Server systems.
  • Inventory endpoints and servers using the CPE list to confirm patch coverage across all supported branches.
  • Verify Secure Boot is enabled in firmware settings and that the revocation database (dbx) is current.

Patch Information

Microsoft published fixes through its standard cumulative update channel. Consult the Microsoft CVE-2024-37970 Update Guide for KB article numbers mapped to each supported Windows build, and deploy through Windows Update, WSUS, Microsoft Update Catalog, or Intune.

Workarounds

  • Restrict adjacent network exposure by segmenting management, PXE, and imaging networks away from user VLANs.
  • Require user awareness training to reduce the likelihood of the user interaction component being triggered.
  • Enforce BitLocker with TPM+PIN to raise the cost of pre-boot tampering until patches are deployed.
  • Enable Windows Defender Device Guard and Hypervisor-Protected Code Integrity (HVCI) where supported.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.