logo

UEFI DBX Update Guidance Targets Vulnerable Vendor-Signed Boot Applications

ID: 73d8f027-e3ef-5593-a73d-c137a1fc5a51

STIX ID: report--73d8f027-e3ef-5593-a73d-c137a1fc5a51

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Divya

...
...

A newly disclosed UEFI vulnerability (VU#457458) allows attackers to abuse legitimately signed UEFI applications (and some GRUB2 modules) to execute arbitrary code in the pre-boot phase, enabling persistent bootkits and bypassing Secure Boot. Researchers (ESET) and CERT/CC advise applying vendor firmware updates and updating the UEFI DBX revocation list to block the identified vulnerable binaries across affected vendors (Acer, AMD, ASUS, Gigabyte, Toshiba, etc.).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.