{"id":585966,"date":"2026-07-14T23:02:14","date_gmt":"2026-07-14T23:02:14","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/585966\/"},"modified":"2026-07-14T23:02:14","modified_gmt":"2026-07-14T23:02:14","slug":"microsoft-signed-legacy-shims-undermine-secure-boot","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/585966\/","title":{"rendered":"Microsoft-Signed Legacy Shims Undermine Secure Boot"},"content":{"rendered":"<p>                    Eset Finds 11 Microsoft-Signed First-Stage Bootloaders Are Vulnerable to Abuse<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/tiffany-wang-i-7880\" rel=\"nofollow noopener\" target=\"_blank\">Tiffany Wang<\/a>                                                     \u2022<br \/>\n                        July 14, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/microsoft-signed-legacy-shims-undermine-secure-boot-a-32224#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/microsoft-signed-legacy-shims-undermine-secure-boot-image_large-3-a-32224.jpg\" alt=\"Microsoft-Signed Legacy Shims Undermine Secure Boot\" class=\"img-responsive \"\/><br \/>\n                Eset identified 11 Microsoft-signed legacy UEFI shim bootloaders with a vulnerability that enables attackers to bypass Secure Boot and install bootkits. (Image: Shutterstock)            <\/p>\n<p>Some Microsoft-signed first-stage bootloaders have grown vulnerable with age. Their entire job to establish trust can be exploited to bypass Secure Boot protections, researchers found.<\/p>\n<p><b>See Also:<\/b> <a href=\"https:\/\/www.bankinfosecurity.com\/beat-breach-outsmart-attackers-secure-cloud-a-32006?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Beat the Breach: Outsmart Attackers and Secure the Cloud<\/a><\/p>\n<p>Each of the 11 small pieces of code called shims, <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/forgotten-uefi-shims-undermining-secure-boot\/#wont-expiring-microsoft-uefi-certificates-solve-this\" target=\"_blank\" rel=\"nofollow noopener\">identified<\/a> by security firm Eset, can be used to execute untrusted code during system boot on millions of machines using the modern firmware architecture Unified Extensible Firmware Interface that still trusts the old shims&#8217; Microsoft certificate.<\/p>\n<p>The vulnerability in shims at or below version 0.9, tracked as <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-8863\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-8863<\/a> and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-10797\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-10797<\/a>, enables attackers to deploy malicious bootkits, such as Bootkitty, HybridPetya or BlackLotus, before the operating system loads, even when UEFI Secure Boot is enabled. CVE-2026-8863 is listed as a high severity flaw, with a CVSS v3.1 base score of 7.8 assigned by the CISA Authorized Data Publisher.<\/p>\n<p>Although Microsoft has <a href=\"https:\/\/kb.cert.org\/vuls\/id\/616257\" target=\"_blank\" rel=\"nofollow noopener\">revoked<\/a> the mistrusted shims found by researchers, attackers can bring their own copy of the vulnerable shims to any UEFI system that still trusts the Microsoft third-party UEFI certificate, spreading damage beyond systems with the affected software.<\/p>\n<p>A shim <a href=\"https:\/\/kb.cert.org\/vuls\/id\/616257\" target=\"_blank\" rel=\"nofollow noopener\">acts<\/a> as a bridge between the UEFI firmware and the operating system, according to CERT Coordination Center. It is signed with the &#8220;Microsoft Corporation UEFI CA 2011&#8221; certificate widely used for third-party boot components to run under Secure Boot.<\/p>\n<p>&#8220;An attacker could exploit these vulnerable shim bootloaders using a bring your own vulnerable driver-style technique to execute arbitrary code during the early boot phase, prior to operating system initialization, thereby bypassing Secure Boot protections,&#8221; CERT\/CC said.<\/p>\n<p>Once the firmware loads the shim and validates its signature, the shim transfers control to second-stage bootloaders that &#8220;extend the trust chain even further,&#8221; said Eset Senior Malware Researcher Martin Smol\u00e1r. A shim can trust anywhere from a few to up to 100 second-stage binaries.<\/p>\n<p>&#8220;Exploitation of each reported shim is not just about a single bug or two that can be found in these old shims directly,&#8221; Smol\u00e1r said. &#8220;In fact, the attack surface is extended by the shims&#8217; trusted, second-stage bootloaders, mostly GRUB 2, which &#8211; like the shims themselves &#8211; may include outdated versions with known vulnerabilities.&#8221;<\/p>\n<p>One Oracle Linux shim, for example, trusted a binary vulnerable to CVE-2015-5281, a Secure Boot bypass flaw that allows local users to execute unverified code through a crafted configuration file.<\/p>\n<p>Signing timestamps of the binaries trusted by the revoked shims span from 2013 to 2025, Smol\u00e1r said, meaning they could be old enough to fall for known vulnerabilities such as BootHole, which <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-10713\" target=\"_blank\" rel=\"nofollow noopener\">allows<\/a> a privileged attacker to bypass Secure Boot protection through Grub 2 in Linux distributions.<\/p>\n<p>While new improvements were introduced to shims over the years, many third-party vendors have taken available versions of the shim source code that can be outdated and vulnerable to build their own binaries.<\/p>\n<p>For example, an older Microsoft-signed shim can ignore the Machine Owner Key denylist introduced in newer versions, allowing attackers to load binaries signed with a revoked MOK certificate, Smol\u00e1r said.<\/p>\n<p>&#8220;What makes these old shims dangerous is not a novel vulnerability. It&#8217;s that no new vulnerability is needed to bypass UEFI Secure Boot,&#8221; Smol\u00e1r said. &#8220;An attacker needs no complicated exploitation primitives \u2013 only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"Eset Finds 11 Microsoft-Signed First-Stage Bootloaders Are Vulnerable to Abuse Tiffany Wang \u2022 July 14, 2026 \u00a0 \u00a0&hellip;\n","protected":false},"author":2,"featured_media":585967,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[43288,248806,18,43285,248809,19,17,248807,82,248808],"class_list":["post-585966","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-bootkit","tag-cve-2026-8863","tag-eire","tag-eset","tag-grub2-vulnerabilities","tag-ie","tag-ireland","tag-microsoft-secure-boot","tag-technology","tag-uefi-shim"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116920827636499229","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/585966","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=585966"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/585966\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/585967"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=585966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=585966"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=585966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}