
Researchers at ESET identified a significant vulnerability in Microsoft’s Secure Boot mechanism, discovering that 11 firmware images known as “shims” remained signed by Microsoft despite containing known defects. These shims, some dating back to 2013, were designed to extend Secure Boot protections to Linux devices and utility software but were never revoked once vulnerabilities were identified.
Secure Boot, introduced in 2012, functions as a critical defense against firmware-level infections called bootkits. The protection works by enforcing a chain of digitally signed code during the boot process. However, the unrevoked shims can be exploited using simple techniques accessible to novice attackers, allowing them to completely circumvent this security layer. Once installed on a device, malicious firmware loaded through these shims can persist even after operating system reinstallation or hard drive replacement.
The vulnerability affects both Windows and Linux users, as the shims can be installed on devices running either operating system. Historical bootkits attributed to state actors and other threat groups, including those from 2018 through 2023, demonstrate the real-world threat that Secure Boot was designed to prevent. The compromise is particularly concerning because it requires only basic knowledge to exploit and no new vulnerabilities—attackers need only access to the old, still-trusted shim binaries.
The root cause appears connected to Secure Boot’s inherent complexity. Microsoft oversees a intricate system of revocation databases, version-based enforcement mechanisms, and certificate hierarchies that govern which code can execute during startup. The company ultimately revoked the 11 problematic shims in June following disclosure by ESET to security authorities, but the extended period during which they remained active highlights potential systemic weaknesses in the framework’s implementation and oversight.
Security experts have criticized the broader architecture, noting that Microsoft’s central role as the root of trust for the entire UEFI platform, combined with the complexity of managing numerous signed components, has created vulnerabilities that undermine Secure Boot’s intended protections.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI