UEFI Secure Boot Bypass: 11 Microsoft-Signed Shims, Some Over a Decade Old, Trusted by Every UEFI Computer — No Exploit Needed, Bootkits Load Before EDR
ESET researcher Martin Smolár discovered 11 old Microsoft-signed UEFI shim bootloaders — some over a decade old — that could bypass Secure Boot on virtually every UEFI computer in the world with nothing more than a file copy. No new exploit needed. Affected: all UEFI systems trusting Microsoft Corporation UEFI CA 2011, regardless of OS. Enables deployment of Bootkitty, HybridPetya, BlackLotus — bootkits that run before the OS, before EDR, before AV, and survive OS reinstalls. Microsoft revoked the 11 binaries via June 9 Patch Tuesday dbx update. ESET cannot confirm how many additional unrevoked vulnerable shims remain undiscovered.
