Microsoft's Secure Boot Leaves Windows and Linux Vulnerable for Over a Decade

Security researchers at ESET reveal that Microsoft's Secure Boot, an industry standard designed to protect devices from firmware infections, has been trivial to bypass for 13 of its 14 years of existence. The discovery centers on 11 firmware shim images, some dating back to 2013, that contain known vulnerabilities but remain digitally signed by Microsoft. These shims, originally created to extend Secure Boot protection to Linux devices and utility software, have been left unrevoked despite their flaws.

The threat affects both Windows and Linux users, as attackers can exploit these forgotten shims to completely circumvent Secure Boot protections. Once bypassed, malicious firmware can be installed that loads early in the boot process and persists even after the operating system is reinstalled or the hard drive is replaced. ESET researcher Martin Smolár notes that no novel vulnerability or complicated techniques are needed—attackers only require a copy of an old, trusted shim and a basic understanding of how UEFI shims function.

Secure Boot was introduced in 2012 specifically to combat bootkits, a class of malicious firmware that can infect devices when attackers have even brief physical access. The failure by Microsoft to properly revoke vulnerable shim images represents a significant breakdown in the certificate management process that underpins the security feature. The company has not yet publicly detailed its plans for addressing the outstanding vulnerable shims.

Read More at the original source →