news.mlab.sh
Back to the feed
vulnerability

Long-Lived Vulnerability in Microsoft Secure Boot

High
Summary

A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsigned shims – used to extend Secure Boot to Linux – could be easily bypassed, allowing attackers to disable the protection entirely. This represents a significant security gap that could be exploited to compromise vulnerable systems.

Microsoft’s Secure Boot, a widely adopted security standard, has suffered from a persistent vulnerability for nearly its entire lifespan. The issue stems from the use of ‘shims,’ small firmware components designed to extend Secure Boot’s protection to Linux devices and utility software. Researchers at ESET identified 11 firmware images, dating back to at least 2013, that were known to be defective but continued to be signed by Microsoft. These shims can be bypassed using a relatively simple technique, requiring no specialized knowledge beyond basic hacking skills. The core problem is Microsoft’s failure to revoke these images once vulnerabilities were identified, allowing attackers to disable Secure Boot entirely, effectively negating the protection embedded within the UEFI firmware of the device’s motherboard.

Read the full article at Schneier on Security