tech

Microsoft's Secure Boot has been broken for a decade and no one noticed until now

Old and forgotten “shims” Microsoft failed to revoke have made Secure Boot bypasses simple.

Microsoft's Secure Boot has been broken for a decade and no one noticed until now

TL;DR

  • Microsoft's Secure Boot, designed to prevent firmware infections, has been trivially bypassable for 13 years.
  • Researchers found 11 vulnerable firmware images (shims) that were still digitally signed by Microsoft, some dating back to 2013.
  • These old shims allow novice hackers to circumvent Secure Boot, a feature embedded in a device's UEFI.
  • The bypass is possible because Microsoft failed to revoke the compromised shims, even after vulnerabilities were discovered.
  • The threat impacts both Windows and Linux users, as attackers can install persistent malicious firmware.
  • Secure Boot was introduced in 2012 to combat bootkits, but this flaw undermines its effectiveness.
  • The complexity of Secure Boot's database management (db and dbx) and revocation methods (SBAT, SVN) may have contributed to the oversight.
  • Microsoft revoked the vulnerable shims in June after the issue was brought to their attention by ESET.
  • While Windows 11 Secured-core PCs and systems updated with Microsoft's June patch are likely protected, older systems and Linux users should verify their status.