11 Signed Linux UEFI Shims Bypass Secure Boot
š High |Ā Source: The Hacker News Researchers have identified 11 older UEFI shim applications that were legitimately signed by Microsoft but contain vulnerabilities allowing attackers to bypass Secure Boot, the firmware-level protection that ensures only trusted software loads at system startup. An attacker with physical or privileged access could exploit these shims to run unsigned, malicious code before the operating system loads, potentially deploying persistent firmware-level malware known as bootkits. This is significant because the shims carry a valid Microsoft signature, meaning many systems will trust them by default without additional configuration. ...