Microsoft’s Secure Boot Has Been Broken for a Decade and Nobody Noticed

Researchers at ESET have found that Microsoft’s Secure Boot — the industry-standard firmware protection built into Windows and Linux devices — has been trivially bypassable for 13 of its 14 years of existence.

The discovery centers on 11 firmware images called shims, dating as far back as 2013. Shims were designed to extend Secure Boot to Linux and utility software. The problem: Microsoft kept signing these shims even after vulnerabilities were found in them. Any novice attacker can use the old, defective shims to completely bypass Secure Boot and install malicious firmware that persists through OS reinstalls and hard drive swaps.

The threat affects both Windows and Linux users. Once an attacker has installed malicious firmware via this bypass, it loads early in the boot process and is invisible to normal security scans. Traditional antivirus won’t catch it.

Microsoft controls the signing process for shims and failed to revoke the known-vulnerable images. The fix requires Microsoft to revoke the defective certificates and issue updated shims — something that should have happened years ago.

References


This article was originally reported by Ars Technica. Rewritten and published by The Coolest Info.