Microsoft Secure Boot Flaw Persisted for 13 Years, Undermining Firmware Security
A critical vulnerability in **Microsoft's Secure Boot** has reportedly been bypassable for 13 of its 14 years of existence, leaving Windows and Linux devices susceptible to firmware infections. Researchers at **ESET** uncovered the flaw, stemming from **Microsoft's** failure to revoke compromised "shims" used to extend Secure Boot functionality.
For over a decade, **Microsoft's Secure Boot**, an industry-wide standard designed to protect devices from firmware-level attacks, has contained a significant vulnerability that could be exploited with relative ease.
The flaw, discovered by security researchers at **ESET**, reveals that the protection mechanism, embedded within a device's **UEFI (Unified Extensible Firmware Interface)**, has been trivial to bypass for most of its operational life.
The core of the issue lies with **Microsoft's** oversight in managing digital signatures for specific software components known as "shims." Shims were developed to extend **Secure Boot's** protection to **Linux** devices and various utility software.
**ESET** identified at least 11 such firmware images, some dating back to 2013, that were known to be defective but remained signed by **Microsoft**. This allowed malicious actors, even those with limited technical expertise, to leverage these unrevoked shims to completely circumvent **Secure Boot's** intended protections.
The gaffe highlights a critical failure in the revocation process, where **Microsoft**, responsible for overseeing the signing of these shims, did not withdraw the publicly available, vulnerable images once their weaknesses were identified. This extended period of vulnerability underscores the complex challenges in maintaining firmware integrity across a vast ecosystem.