- Microsoft's Secure Boot has been broken for a decade, with vulnerabilities in old UEFI shims going unnoticed until now, according to a report by ESET.
- Eleven outdated Microsoft-signed UEFI applications have been discovered that can be exploited to bypass Secure Boot on most systems.
- These vulnerable UEFI applications, primarily older versions of the shim bootloader, can allow attackers to execute untrusted code during system startup.
- The vulnerability stems from the fact that these older shims are signed with a Microsoft certificate authority that has not been explicitly revoked for these specific applications.
- Attackers can leverage the 'bring your own vulnerable driver' (BYOVD) technique to bypass security mechanisms and gain arbitrary code execution before the operating system loads.
- The issue affects various Linux distributions and software from vendors like Red Hat, Oracle, and OpenSuse.
- Microsoft failed to revoke the publicly available images once vulnerabilities were found in them, leading to this security gap.
- The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective.
- Microsoft finally revoked the vulnerable shims in its regular monthly patch release in June, after ESET brought them to CERT's and Microsoft's attention.
- The bypass can evade detection by operating system security controls and endpoint detection and response (EDR) solutions, potentially allowing for persistent access.
- Windows and Linux users are both at risk since the shim can be installed on devices running either operating system.
- Old shims can be used to completely circumvent the protection embedded into the UEFI of the device’s motherboard.
- Even the expiration of the Microsoft certificate that signed the shims isn’t enough to revoke the ones ESET identified.
- HD Moore, a firmware security expert, criticized the situation as a solid rebuke of the entire secure boot model.
ESET researchers have identified 11 outdated UEFI shims that can bypass Secure Boot, a critical security feature designed to prevent unauthorized code execution during system startup. These shims, some dating back to 2013, remain signed by Microsoft despite known vulnerabilities.8
The vulnerabilities allow attackers to leverage the "bring your own vulnerable driver" (BYOVD) technique, enabling them to execute untrusted code even when Secure Boot is active. This poses a significant risk to both Windows and Linux users, as the shims can be installed on devices running either operating system.
According to ESET researcher Martin Smolár, “What makes these old shims dangerous is not a novel vulnerability. It’s that no new vulnerability is needed to bypass UEFI Secure Boot.” The issue arises from Microsoft’s failure to revoke these shims, which were known to be defective for over a decade.

The CERT Coordination Center highlighted that vendor-specific bootloaders were not updated to address these vulnerabilities, leading to a supply chain exposure. The bypass can evade detection by operating system security controls, allowing for persistent access that survives reboots and reinstallation.10
“This is a solid rebuke of the entire secure boot model,” said HD Moore, a firmware security expert. The discovery raises serious questions about the effectiveness of Secure Boot, which has been trivial to bypass for most of its 14-year existence.14
Microsoft finally revoked the shims in its June patch release after ESET alerted them to the vulnerabilities, but the damage may already be done.9
“The vulnerable shims, signed with an expired but unrevoked Microsoft certificate, enable attackers to deploy persistent UEFI bootkits that survive OS reinstallation and evade EDR solutions. ESET researcher Martin Smolár noted that no new vulnerability is needed—only a copy of an old, still-trusted shim binary—rendering Secure Boot trivial to bypass.”
