• News/
  • darkreading-20260715211919

Forgotten Bootloaders Expose Secure Boot Blind Spot

Dark Reading
·
Jai Vijayan
·
Published Jul 15, 2026
·
Updated

Researchers recently discovered 11 vulnerable but still trusted UEFI shim bootloaders that attackers could have used to bypass Secure Boot on systems that trust Microsoft's third-party UEFI signing certificate. The Unified Extensible Firmware Interface (UEFI) consists of motherboard software that connects that operating system and hardware. Microsoft revoked the vulnerable bootloaders in June through Secure Boot revocation updates after ESET reported the findings, but unpatched systems may continue to trust the components and remain exposed to boot-level attacks. A shim bootloader is a small program launched by Unified Extensible Firmware Interface (UEFI) firmware on Secure Boot-enabled systems that acts as a bridge between the firmware and the operating system bootloader. In Linux environments, shims allow Linux distributions to boot on Secure Boot-enabled UEFI systems by serving as a trusted first-stage bootloader that verifies and launches the rest of the Linux boot process. As ESET explained in a report this week, a UEFI shim bootloader is "a small, minimal first-stage bootloader that Microsoft can vet and sign once, and which then creates a secondary trust anchor for the rest of the Linux distribution-specific boot stack — usually GRUB 2 and the Linux kernel." Shims eliminate the need for Microsoft to sign every Linux bootloader, while maintaining the integrity of the Secure Boot trust chain. The 11 shim bootloaders ESET discovered were version 0.9 or earlier, placing th...

Read full article

Affected Software

2 affected components
Microsoft UEFI shim bootloaders (Microsoft third-party UEFI signing)<=0.9
Microsoft UEFI shim bootloaders signed before 2017 (Microsoft Corporation UEFI CA 2011 trust)<2017
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of vulnerable UEFI shim bootloaders that can bypass Secure Boot due to a trusted third-party signing certificate from Microsoft.

2

What security implications are discussed?

The security implications include the potential for attackers to exploit these vulnerable bootloaders to compromise systems utilizing Secure Boot.

3

What products or software are affected?

The affected products include Microsoft UEFI shim bootloaders, particularly those signed before 2017.

4

Who discovered the vulnerabilities in the UEFI bootloaders?

The article indicates that researchers were responsible for discovering the vulnerabilities in the UEFI bootloaders.

5

How many vulnerable UEFI shim bootloaders were identified?

Researchers discovered a total of 11 vulnerable UEFI shim bootloaders.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203