Microsoft · Oracle · Russia · Ars Technica
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Compiled by KHAO Editorial — aggregated from 1 source + 1 reference discovered via search. See llms.txt for citation guidance.
◌ Single Source
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence.
Key facts
- Without Secure Boot, attackers with brief physical access to a device—even when it’s turned off—can install bootkits similar to LoJax used by Russia state hackers in 2018, MosaicRegressor found
- The Oracle shim, for instance, signs a binary vulnerable to CVE-2015-5381
- An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence
- A list of all 11 shims compiled by CERT shows that some were used by Linux distributors such as Redhat, OpenSuse, and Oracle
Summary
The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. The threat extends to Windows and Linux users alike, since the shim can be installed on devices running both operating systems. “What makes these old shims dangerous is not a novel vulnerability,” ESET researcher Martin Smolár wrote Tuesday. Secure boot was introduced in 2012 to blunt the threat of bootkits, the term for such malicious firmware.