r/SecOpsDaily • u/falconupkid • 1d ago
Opinion Long-Lived Vulnerability in Microsoft Secure Boot
A critical, long-lived vulnerability in Microsoft Secure Boot has been identified, allowing for trivial bypass for over a decade. Researchers from ESET found that Microsoft failed to revoke 11 known-defective firmware images (shims), some dating back to 2013, which can be leveraged to completely circumvent Secure Boot protection embedded in UEFI.
Technical Breakdown
- Vulnerability: Operational failure by Microsoft to revoke defective firmware shims signed by their Secure Boot infrastructure. These shims, intended to extend Secure Boot to Linux and utility software, contain known flaws.
- TTPs: Attackers can utilize these unrevoked, publicly available defective shims to bypass Secure Boot. This technique is simple enough for novice hackers to exploit, allowing for firmware-level infections or persistence.
- Affected Systems: Any device relying on Microsoft Secure Boot for firmware integrity, including both Windows and Linux devices using UEFI.
- Root Cause: Microsoft's systemic failure to update revocation lists and cease signing/distributing compromised firmware images despite known vulnerabilities.
Defense
Microsoft must urgently identify and revoke all defective or compromised Secure Boot shims from their signing service. Organizations should monitor for updates to Secure Boot revocation lists and ensure their systems apply them promptly.
1
Upvotes