Microsoft’s Secure Boot Has Been Broken for a Decade and No One Noticed Until Now
ESET said the shims authorize vulnerable components and can let attackers bypass Secure Boot on Windows and Linux systems.
- Researchers at ESET discovered 11 vulnerable UEFI 'shim' bootloaders dating back to 2013 that remained trusted by Microsoft for years despite known flaws, allowing attackers to bypass Secure Boot on Windows and Linux machines.
- Secure Boot, introduced in 2012 to prevent boot-chain attacks, relies on Microsoft as the root of trust to sign all code including shims that let non-Microsoft software run; the affected shims came from vendors like Red Hat, openSUSE, and Oracle but were never revoked.
- The identified shims authorize components with known vulnerabilities, including an Oracle shim vulnerable to CVE-2015-5381 that requires minimal skill to exploit, while others lack critical protections like MOK deny-list and SBAT enforcement developed after their release.
- Attackers exploiting these shims can load malicious firmware before the operating system starts, potentially persisting through OS reinstalls and hardware changes. Windows users with June updates are protected, though Linux users must verify patches with their distributor.
- The vulnerability exposes fundamental flaws in Secure Boot's architecture, with HD Moore, CEO and founder of runZero, arguing 'the whole ecosystem is somewhat broken and needs a reboot' due to poorly tracked signed components and Microsoft's unchecked role as UEFI root of trust.
16 Articles
16 Articles
Microsoft finally patched Secure Boot bypasses that were hiding in plain sight since 2013
The issue affects 11 shim binaries that were still signed and accepted by systems enforcing Secure Boot. That signature is what allows code to run during the boot process. If a trusted component is compromised, everything that follows can be affected.Read Entire Article
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, which were invented to extend Sec…
ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot
ESET researchers discovered 11 old, Microsoft-signed, UEFI applications that allow bypassing UEFI Secure Boot on the majority of UEFI-based systems.An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware.Exploitation is not limited to systems with the affected software or Operation system (OS) installed, as attackers can bring their…
For more than a decade, Secure Boot could be eliminated in Windows with simple means. Security researchers have found out this out. Why attackers have been able to do this. read more on t3n.de
Security researchers have revealed a major vulnerability affecting Microsoft's Secure Boot system for thirteen years. Designed to protect your PC from malware at startup, Secure Boot could be bypassed by hackers to install malware on Windows and Linux.
Coverage Details
Bias Distribution
- 67% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







