Forgotten UEFI shims broke Secure Boot for 13 years

Researchers at ESET discovered that Microsoft’s Secure Boot has been effectively broken for most of its existence. The culprit is a set of forgotten UEFI shim bootloaders that Microsoft signed years ago and never revoked. Eleven specific shims, all version 0.9 and below, can be used to bypass Secure Boot on virtually any system, and […]

Microsoft Secure Boot Bypassed by Decade-Old Unsigned Bootloaders

ESET researchers have found 11 old Microsoft-signed UEFI shim bootloaders that let attackers bypass Secure Boot entirely. The bootloaders date back to 2013, version 0.9 and earlier, and Microsoft never revoked their signatures. Secure Boot was introduced with Windows 8 in 2012 as a hardware-level protection. It checks that only trusted, signed bootloaders run during […]