Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known…
Microsoft's Secure Boot, a standard designed to safeguard Windows and Linux devices from firmware infections, has had a critical vulnerability for the majority of its 14-year history. Researchers at security firm ESET uncovered this flaw, which allows for bypassing the protection with relative ease. The issue stems from 11 firmware images, at least one dating back to 2013, that were previously deemed defective but were still signed by Microsoft.
These images, known as shims, were created to extend Secure Boot functionality to Linux devices and utility software. Utilizing a method as simple as one a novice hacker could execute, these outdated shims can effectively circumvent the security measures embedded in the UEFI of a device's motherboard. Microsoft, responsible for signing these shims, failed to revoke the publicly available images after vulnerabilities were discovered, leading to this significant security lapse.
Written by urgent.news from Schneier on Security's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.