Security · 1h ago
Microsoft Secure Boot Bypassed for 13 Years via Forgotten Shims
ESET researchers found 11 firmware shims signed by Microsoft that allow trivial bypass of Secure Boot, with one dating back to 2013. The vulnerability affects Windows and Linux devices using UEFI, enabling novice hackers to circumvent the protection. Microsoft failed to revoke the defective shims after vulnerabilities were discovered.
Meridian48 take
This is a staggering oversight from Microsoft, undermining a foundational security feature for over a decade and highlighting the dangers of forgotten code in the firmware supply chain.
microsoft-secure-bootfirmware-vulnerability