CyberSecurity News
Long-Lived Vulnerability in Microsoft Secure Boot
AI summary
Microsoft's Secure Boot has had a significant vulnerability for most of its 14-year existence. The vulnerability allows for a trivial bypass of the security feature, which was designed to protect devices from firmware infections. Researchers at ESET made the discovery after finding 11 defective firmware images, including one from 2013, that were still signed by Microsoft. These images, known as shims, were created to extend Secure Boot to Linux devices and utility software. The vulnerability has existed for 13 years, indicating a long-standing issue with the Secure Boot system. The discovery highlights a major flaw in a security standard that was intended to provide protection for Windows and Linux devices.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to Schneier on Security.

