Trusted UEFI Certificates Exploited to Bypass Kernel Security Protections
ID: 97390505-f475-5618-8122-43b66f28e962
STIX ID: report--97390505-f475-5618-8122-43b66f28e962
Feed Name: Cyber Press
Threat Score
A critical UEFI firmware vulnerability discovered by ESET’s Martin Smolar allows attackers to weaponize vendor-signed UEFI applications (e.g., shells, GRUB2) to bypass Secure Boot, run arbitrary code in the pre-boot stage, and achieve persistent, EDR‑evading compromises across systems from numerous major vendors; the report lists affected binaries and hashes and advises applying vendor firmware updates, updating DBX/DB revocations, verifying DBX integrity, and restricting access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
