news.mlab.sh
Back to the feed
threat-intel

Old UEFI Shims Expose Systems to Secure Boot Bypass

High
Summary

A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating back to 2013, were previously trusted by Secure Boot, but Microsoft has now revoked them. System administrators need to update their signature databases to prevent exploitation.

A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating back to 2013, were previously trusted by Secure Boot, but Microsoft has now revoked them. System administrators need to update their signature databases to prevent exploitation. ESET reported the findings to CERT/CC in February 2026, and in June, Microsoft revoked all vulnerable applications and added them to the UEFI DBX (Forbidden Signature Database). The vulnerable shims extend the attack surface by allowing attackers to execute untrusted code during the boot process. These shims were signed and documented after a vetting process, but those approved before then are not documented, and many old, still-trusted shims may remain, potentially exposing systems to attacks. CERT/CC advises system administrators to update their signature databases before applying DBX revocations, emphasizing the need to update trusted boot applications and certificates first, followed by deployment of the revocation list. Failure to follow this order may cause systems to reject newly updated boot components. This vulnerability affects systems that trust Microsoft Corporation’s UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system.

Read the full article at SecurityWeek