Microsoft Secure Boot Flaw Persisted for 13 of Its 14 Years
ESET researchers find a Secure Boot vulnerability that went unpatched for 13 years, letting old signed shims bypass UEFI firmware protection.
Security researchers at ESET have uncovered that Secure Boot, the firmware protection standard Microsoft created to shield Windows and Linux devices from firmware-level infections, has carried a serious vulnerability for nearly its entire lifespan. The team identified 11 signed shim binaries, at least one dating to 2013, known to be defective yet left signed and publicly available by Microsoft.
Shims were designed to extend Secure Boot support to Linux systems and utility software. Attackers can exploit these outdated, forgotten shims using a technique simple enough for novice hackers to execute, fully bypassing the protection embedded in a device's UEFI firmware.
The root cause is Microsoft's failure, as the authority overseeing shim signing, to revoke these publicly known vulnerable images once flaws were discovered. The finding underscores a long-standing gap in firmware security governance and highlights the critical importance of timely certificate and signature revocation in boot-chain trust models.