CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Long-Lived Vulnerability in Microsoft Secure Boot

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3449

As cited

Copy frozen at (site build).

vulnerabilities

Long-Lived Vulnerability in Microsoft Secure Boot

ESET researchers discovered that Microsoft's Secure Boot mechanism contained a long-lived vulnerability affecting 13 of its 14 years of operation. The flaw stemmed from Microsoft's failure to revoke 11 defective firmware shim images, some dating to 2013, that remained signed despite known vulnerabilities and could be exploited by attackers to circumvent the protection entirely using relatively simple techniques.

Why it matters: Windows and Linux device manufacturers and administrators rely on Secure Boot to prevent firmware-level attacks, so this unpatched bypass puts endpoints at risk of persistent compromise that survives operating system reinstalls until the firmware itself is updated.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Long-Lived Vulnerability in Microsoft Secure Boot

ESET researchers discovered that Microsoft's Secure Boot mechanism contained a long-lived vulnerability affecting 13 of its 14 years of operation. The flaw stemmed from Microsoft's failure to revoke 11 defective firmware shim images, some dating to 2013, that remained signed despite known vulnerabilities and could be exploited by attackers to circumvent the protection entirely using relatively simple techniques.

Why it matters: Windows and Linux device manufacturers and administrators rely on Secure Boot to prevent firmware-level attacks, so this unpatched bypass puts endpoints at risk of persistent compromise that survives operating system reinstalls until the firmware itself is updated.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary