---
id: CVE-2024-8105
title: >-
  A vulnerability exists in UEFI implementations that use a hard-coded
  software-based Platform Key (PK)
summary: >-
  A vulnerability exists in UEFI implementations that use a hard-coded
  software-based Platform Key (PK). An attacker in possession of the
  corresponding PK private key can sign arbitrary UEFI executables or firmware
  components, causing them…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
published: '2024-08-26'
updated: '2026-06-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-8105'
references:
  - url: >-
      https://github.com/binarly-io/Vulnerability-REsearch/blob/main/PKfail/BRLY-2024-005.md
    label: cret@cert.org
  - url: 'https://kb.cert.org/vuls/id/455367'
    label: cret@cert.org
  - url: >-
      https://security.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-FJ-ISS-2024-072412-Security-Notice.pdf
    label: cret@cert.org
  - url: 'https://uefi.org/specs/UEFI/2.9_A/32_Secure_Boot_and_Driver_Signing.html'
    label: cret@cert.org
  - url: 'https://www.binarly.io/advisories/brly-2024-005'
    label: cret@cert.org
  - url: 'https://www.gigabyte.com/us/Support/Security/2205'
    label: cret@cert.org
  - url: >-
      https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-07-25-001.html
    label: cret@cert.org
  - url: 'https://www.supermicro.com/en/support/security_PKFAIL_Jul_2024'
    label: cret@cert.org
  - url: 'https://www.kb.cert.org/vuls/id/455367'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00274
epssPercentile: 0.20072
ingestedAt: '2026-06-29T13:24:33.958Z'
---

## Overview

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
