Researchers recently discovered 11 vulnerable but still trusted UEFI shim bootloaders that attackers could have used to bypass Secure Boot on systems that trust Microsoft's third-party UEFI signing certificate. The Unified Extensible Firmware Interface (UEFI) consists of motherboard software that connects that operating system and hardware. Microsoft revoked the vulnerable bootloaders in June through Secure Boot revocation updates after ESET reported the findings, but unpatched systems may continue to trust the components and remain exposed to boot-level attacks. A shim bootloader is a small program launched by Unified Extensible Firmware Interface (UEFI) firmware on Secure Boot-enabled systems that acts as a bridge between the firmware and the operating system bootloader. In Linux environments, shims allow Linux distributions to boot on Secure Boot-enabled UEFI systems by serving as a trusted first-stage bootloader that verifies and launches the rest of the Linux boot process. As ESET explained in a report this week, a UEFI shim bootloader is "a small, minimal first-stage bootloader that Microsoft can vet and sign once, and which then creates a secondary trust anchor for the rest of the Linux distribution-specific boot stack — usually GRUB 2 and the Linux kernel." Shims eliminate the need for Microsoft to sign every Linux bootloader, while maintaining the integrity of the Secure Boot trust chain. The 11 shim bootloaders ESET discovered were version 0.9 or earlier, placing th...
Forgotten Bootloaders Expose Secure Boot Blind Spot
Dark Reading
·Jai Vijayan
·Published Jul 15, 2026
·Updated
Affected Software
2 affected components
Microsoft UEFI shim bootloaders (Microsoft third-party UEFI signing)<=0.9
Microsoft UEFI shim bootloaders signed before 2017 (Microsoft Corporation UEFI CA 2011 trust)<2017
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of vulnerable UEFI shim bootloaders that can bypass Secure Boot due to a trusted third-party signing certificate from Microsoft.
2
What security implications are discussed?
The security implications include the potential for attackers to exploit these vulnerable bootloaders to compromise systems utilizing Secure Boot.
3
What products or software are affected?
The affected products include Microsoft UEFI shim bootloaders, particularly those signed before 2017.
4
Who discovered the vulnerabilities in the UEFI bootloaders?
The article indicates that researchers were responsible for discovering the vulnerabilities in the UEFI bootloaders.
5
How many vulnerable UEFI shim bootloaders were identified?
Researchers discovered a total of 11 vulnerable UEFI shim bootloaders.