Microsoft CorporationMicrosoft-signed UEFI shims were found vulnerable, undermining Secure Boot, though Microsoft revoked the binaries.

ESET researchers have discovered 11 old, Microsoft-signed UEFI applications that allow bypassing UEFI Secure Boot on the majority of UEFI-based systems. An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware. Exploitation is not limited to systems with the affected software or operating system installed, as attackers can bring their own copy of the vulnerable binaries to any UEFI system with the Microsoft third-party UEFI certificate enrolled. All UEFI systems with Microsoft third-party UEFI signing enabled are affected, though Windows 11 Secured-core PCs are expected to have this option disabled by default. The vulnerable binaries were revoked by Microsoft.
Microsoft CorporationMicrosoft-signed UEFI shims were found vulnerable, undermining Secure Boot, though Microsoft revoked the binaries.