11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
ID: 4daf7978-3d27-5f74-a2ee-f4c91e9948a4
STIX ID: report--4daf7978-3d27-5f74-a2ee-f4c91e9948a4
Feed Name: The Hacker News
Threat Score
ESET researchers disclosed that eleven legacy Microsoft-signed UEFI shim bootloaders remain trusted by firmware (via the “Microsoft Corporation UEFI CA 2011” certificate) and can be abused to bypass Secure Boot, allowing attackers with boot-modification or administrative capability to run arbitrary code during early boot and deploy persistent UEFI bootkits; Microsoft revoked the affected shims in June 2026 and the issues are tracked as CVE-2026-8863 and CVE-2026-10797.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
