ESET discovers 11 old UEFI shims bypassing Secure Boot; Microsoft's Secure Boot has been broken for a decade unnoticed until now
Martin SmolárHD MooreRed HatCERT Coordination CenterESETopenSUSECERTOracleMicrosoft

ESET discovers 11 old UEFI shims bypassing Secure Boot; Microsoft's Secure Boot has been broken for a decade unnoticed until now

ESET has uncovered 11 outdated UEFI shims that can bypass Secure Boot, a security feature designed to protect systems from malware. These vulnerabilities, present for over a decade, allow attackers to execute untrusted code during startup, raising concerns for both Windows and Linux users.

SC Media SC Media+1 source21h ago
CuriousCats Full Story

ESET researchers have identified 11 outdated UEFI shims that can bypass Secure Boot, a critical security feature designed to prevent unauthorized code execution during system startup. These shims, some dating back to 2013, remain signed by Microsoft despite known vulnerabilities.8

The vulnerabilities allow attackers to leverage the "bring your own vulnerable driver" (BYOVD) technique, enabling them to execute untrusted code even when Secure Boot is active. This poses a significant risk to both Windows and Linux users, as the shims can be installed on devices running either operating system.

According to ESET researcher Martin Smolár, “What makes these old shims dangerous is not a novel vulnerability. It’s that no new vulnerability is needed to bypass UEFI Secure Boot.” The issue arises from Microsoft’s failure to revoke these shims, which were known to be defective for over a decade.

The CERT Coordination Center highlighted that vendor-specific bootloaders were not updated to address these vulnerabilities, leading to a supply chain exposure. The bypass can evade detection by operating system security controls, allowing for persistent access that survives reboots and reinstallation.10

“This is a solid rebuke of the entire secure boot model,” said HD Moore, a firmware security expert. The discovery raises serious questions about the effectiveness of Secure Boot, which has been trivial to bypass for most of its 14-year existence.14

Microsoft finally revoked the shims in its June patch release after ESET alerted them to the vulnerabilities, but the damage may already be done.9

Key Insight
“The vulnerable shims, signed with an expired but unrevoked Microsoft certificate, enable attackers to deploy persistent UEFI bootkits that survive OS reinstallation and evade EDR solutions. ESET researcher Martin Smolár noted that no new vulnerability is needed—only a copy of an old, still-trusted shim binary—rendering Secure Boot trivial to bypass.”
CuriousCats studied:
1
SC MediaSC Media
“Eleven outdated Microsoft-signed Unified Extensible Firmware Interface (UEFI) applications have been discovered that can be exploited to bypass Secure Boot on most systems, according to a recent report by The Hacker News.”
SC Media →
2
Ars TechnicaArs Technica
“An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence.”
Ars Technica →
Ask CuriousCats
Who discovered the UEFI shims bypassing Secure Boot?
What does the vulnerability allow attackers to do?
How long has the Secure Boot issue existed?
Are there other systems affected by similar vulnerabilities?
How does this exploit compare to previous firmware security issues?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
One story brought you here.
CuriousCats brings you everything else worth knowing.
Get CuriousCats