🟠 High | Source: Schneier on Security
A serious vulnerability in Microsoft’s Secure Boot has existed for 13 of its 14 years, allowing attackers to completely bypass firmware-level boot protection. ESET researchers found 11 defective shim images — some dating back to 2013 — that Microsoft signed but never revoked, despite known vulnerabilities. Because these signed shims remain publicly available, even low-skilled attackers can use them to circumvent UEFI Secure Boot protections on affected devices.
Security Architect’s Take: Audit your estate for devices where Secure Boot is relied upon as a security control and verify that UEFI DBX (revocation list) updates have been applied; treat Secure Boot alone as insufficient for firmware integrity assurance and layer it with measured boot, TPM attestation, and endpoint detection capable of identifying pre-OS threats.
Original advisory: Long-Lived Vulnerability in Microsoft Secure Boot