An industry-standard developed by Microsoft to safeguard Windows and Linux devices from firmware attacks has been found to have a significant vulnerability that has existed for 13 of its 14 years. Researchers at ESET discovered that 11 outdated firmware images, known as shims and dating back to at least 2013, remained signed by Microsoft despite being identified as defective. This oversight allows even novice hackers to exploit these shims to bypass the protection built into the Unified Extensible Firmware Interface (UEFI) of devices. The failure stems from Microsoft’s inability to revoke the public availability of these vulnerable images, thereby enabling attackers to install malicious firmware that can persist through operating system reinstalls or hard drive replacements.
Why It Matters
The implications of this discovery affect a wide range of users, as both Windows and Linux systems are at risk due to the nature of the shim’s interoperability. Secure Boot, a feature designed to prevent unauthorized firmware from loading during the boot process, is compromised by these vulnerabilities. Historically, Secure Boot was introduced to enhance system security, but the inability to revoke defective shims undermines that objective. This situation highlights the ongoing challenges in maintaining firmware integrity and the importance of timely updates and revocations in the cybersecurity landscape.
Want More Context? 🔎