
Security researchers at ESET identified a significant vulnerability in Microsoft’s Secure Boot system, which was designed to protect devices from firmware-level infections. The researchers found 11 firmware images known as shims that contained known defects but remained signed by Microsoft for extended periods, with some dating back to 2013.
Shims were originally created to extend Secure Boot functionality to Linux devices and utility software. By exploiting these unsigned revocations, attackers with relatively basic technical knowledge can completely circumvent Secure Boot protections embedded in device motherboards. Once bypassed, attackers can install malicious firmware that loads early in the boot process and persists even after operating system reinstallation or hard drive replacement. The vulnerability affects both Windows and Linux users, though Windows 11 Secured-core PCs may have additional protections by default.
Secure Boot was introduced to counter bootkit threats, which are malicious firmware packages that have been deployed in real-world attacks by state-sponsored actors and other threat groups. The protection is considered critical because it defends against attacks requiring only brief physical access to a device. Microsoft’s failure to revoke the vulnerable shims appears to stem from the complexity of Secure Boot’s architecture, which involves multiple databases and revocation mechanisms with significant technical constraints.
Microsoft revoked the affected shims in its monthly security update released in June after ESET disclosed the issue to the company and CERT. The company has not publicly explained how the revocation lapse occurred. Security experts have criticized the incident as evidence of fundamental design flaws in Secure Boot, particularly Microsoft’s role as the primary trust anchor for the entire UEFI platform and the system’s inability to scale effectively across the diverse ecosystem of signed components.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI