Forgotten UEFI shims undermining Secure Boot
ID: c3c9561c-9476-5503-8aa9-2ff3674f3eaa
STIX ID: report--c3c9561c-9476-5503-8aa9-2ff3674f3eaa
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers identified 11 outdated Microsoft-signed UEFI shim bootloaders (≤0.9) that allow bypassing UEFI Secure Boot on systems trusting Microsoft's third-party UEFI CA; attackers can bring these shims to affected systems to load vulnerable second-stage components (notably old GRUB 2 builds) and execute untrusted code during boot, enabling UEFI bootkits. The report details technical root causes (including CVE-2026-8863 and CVE-2026-10797), coordinated disclosure and Microsoft dbx revocations (June 9, 2026), mitigation steps (install dbx updates / vendor firmware updates), and detection guidance for Windows and Linux.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
