logo

Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue

ID: 58c8ee09-77d2-510f-9460-f2904239f0f8

STIX ID: report--58c8ee09-77d2-510f-9460-f2904239f0f8

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-26

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Binarly disclosed a widespread Secure Boot weakness dubbed "PKFail" after discovering that an AMI Platform Key leaked in 2018 was reused in production firmware by multiple OEMs (including Lenovo, HP, Asus, SuperMicro). Because the compromised PK serves as a root of trust for UEFI Secure Boot, attackers with the private key can manipulate KEK/db/dbx to bypass Secure Boot and deploy persistent bootkits; a proof-of-concept exists and vendors must replace the key and issue firmware updates, though many systems may remain exposed until patches are widely applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.