Long-Lived Vulnerability in Microsoft Secure Boot
ID: 12368216-bb08-5fcf-8d17-9591f3b9218a
STIX ID: report--12368216-bb08-5fcf-8d17-9591f3b9218a
Feed Name: Schneier on Security
Threat Score
Researchers at ESET disclosed that Microsoft-signed 'shim' firmware images used to extend Secure Boot to Linux have remained publicly available and signed despite being defective; at least 11 such shims (some dating to 2013) can be used to trivially bypass UEFI Secure Boot, and Microsoft failed to revoke the vulnerable images, making this a long-lived supply-chain/firmware security weakness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
