CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Forgotten UEFI shims undermining Secure Boot

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6107

As cited

Copy frozen at (site build).

vulnerabilities

Forgotten UEFI shims undermining Secure Boot

ESET researchers identified 11 UEFI shim bootloaders signed by Microsoft that contain vulnerabilities allowing attackers to circumvent UEFI Secure Boot protections. These bootloaders, some containing exploitable flaws from over a decade ago, remain in circulation despite their security risks.

Why it matters: System administrators and firmware vendors need to audit and revoke trust in outdated UEFI shims to prevent attackers from using them to load malicious code during system boot, bypassing a key security boundary.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Forgotten UEFI shims undermining Secure Boot

ESET researchers identified 11 UEFI shim bootloaders signed by Microsoft that contain vulnerabilities allowing attackers to circumvent UEFI Secure Boot protections. These bootloaders, some containing exploitable flaws from over a decade ago, remain in circulation despite their security risks.

Why it matters: System administrators and firmware vendors need to audit and revoke trust in outdated UEFI shims to prevent attackers from using them to load malicious code during system boot, bypassing a key security boundary.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary