AGP Picks
View all

ESET finds 11 signed UEFI shims that can bypass Secure Boot

Jul. 23, 2026
By AI, Created 09:29 UTC, Jul 23, 2026, AGP -

ESET researchers identified 11 Microsoft-signed UEFI shim bootloaders that can let attackers bypass Secure Boot on affected UEFI systems. The findings matter because the vulnerable shims can be used to launch bootkits even when Secure Boot is enabled, but Microsoft revocations and system updates can block them.

Why it matters: - The vulnerable shims can let attackers bypass UEFI Secure Boot on UEFI-based devices that trust the Microsoft Corporation UEFI CA 2011 third-party certificate authority. - Attackers can use the shims to run untrusted code during system boot and potentially install malicious UEFI bootkits. - The issue affects devices regardless of the installed operating system.

What happened: - ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft. - The affected shims are version 0.9 and below. - ESET reported the findings to CERT/CC, and the vulnerable UEFI applications were then revoked. - Martin Smolár, an ESET researcher, said the dangerous part is that no new vulnerability is needed to bypass Secure Boot.

The details: - UEFI shim bootloaders are small pieces of code that bridge motherboard UEFI firmware and an operating system. - The discovered shims came from multiple sources, including PC-diagnostic software, Linux distributions, and other UEFI-based utilities. - Attackers do not need the affected software installed on the target device. - Attackers can bring their own copy of a vulnerable shim to any UEFI system that has the Microsoft third-party UEFI certificate enrolled. - ESET said the shims can be blocked by applying the latest UEFI revocations from Microsoft. - Windows systems should receive the update automatically. - Linux updates should be available through the Linux Vendor Firmware Service. - ESET pointed readers to its blogpost on CVE-2024-7344 for broader guidance on detecting or defending against vulnerable signed UEFI bootloaders and UEFI bootkits. - ESET also referenced the blogpost “Forgotten UEFI shims undermining Secure Boot” on WeLiveSecurity.com for more detail.

Between the lines: - The core risk is not a new exploit chain, but the continued trust placed in old Microsoft-signed binaries that were never revoked. - The findings show how third-party signing can create a long tail of legacy trust issues even after newer protections are added. - Smolár said the breadth of the attack surface comes from easily exploitable issues in specific shims, not from one isolated flaw.

What's next: - Device owners and administrators need to apply the latest UEFI revocations and system updates to reduce exposure. - Linux users may need to rely on firmware-service-delivered updates rather than a standard OS patch path. - Security teams will likely keep watching for bootkit activity that uses old, still-trusted shim binaries.

The bottom line: - A small set of outdated, Microsoft-signed UEFI shims can undercut Secure Boot across affected systems until revocations and updates are in place.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Military Industry Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Military Industry Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.