Critical flaw in Shim bootloader impacts major Linux distros
ID: 742256d9-9bdc-5583-9e27-fe7a4078cee2
STIX ID: report--742256d9-9bdc-5583-9e27-fe7a4078cee2
Feed Name: Bleeping Computer
Threat Score
A critical vulnerability (CVE-2023-40547) in the Shim UEFI bootloader's HTTP boot parsing can produce an out-of-bounds write allowing attackers to execute code before the OS loads, bypassing Secure Boot; the report details discovery, exploitation vectors (remote MiTM, local EFI modification, PXE), and remediation guidance including upgrading to Shim 15.8 and updating the UEFI Secure Boot DBX.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
