Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass
ID: 5f48efe9-a070-5fda-a3f0-be6d3c56bd76
STIX ID: report--5f48efe9-a070-5fda-a3f0-be6d3c56bd76
Feed Name: Infosecurity Magazine (News)
ESET disclosed that 11 older Microsoft-signed UEFI shim bootloaders (<= v0.9) contain vulnerabilities allowing attackers to bypass Secure Boot and load unsigned kernels or bootloaders, enabling UEFI bootkits (e.g., Bootkitty, HybridPetya, BlackLotus). The issue stems from legacy shims trusting outdated second-stage loaders (mostly old GRUB2 builds) and ignoring revocation mechanisms (MOK denylist, SBAT); Microsoft published CVEs (CVE-2026-8863, CVE-2026-10797) and revoked the binaries in a June dbx update, while guidance directs Windows to update automatically and Linux users to pull revocations via the Linux Vendor Firmware Service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
