Briefing

Researchers Find 11 Microsoft‑Signed UEFI Apps That Can Bypass Secure Boot

security
by [email protected] (The Hacker News) ·

Patch or update firmware to remove the 11 vulnerable UEFI applications.

What to do now

Update firmware to eliminate the vulnerable UEFI apps and verify Secure Boot integrity.

Summary

Security researchers uncovered 11 legacy Microsoft‑signed Unified Extensible Firmware Interface (UEFI) applications that can be abused to bypass Secure Boot on most modern firmware systems. An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling the deployment of malicious UEFI bootkits or other malware. The findings highlight a critical weakness in the firmware signing process, where outdated applications remain signed and trusted by the firmware. The vulnerability allows attackers to load malicious code before the operating system boots, effectively circumventing the Secure Boot protection that is designed to prevent unauthorized firmware execution. The research team demonstrated how the bypass could be achieved on a variety of hardware platforms, including consumer laptops and enterprise servers. Microsoft has not yet released a patch for these specific UEFI applications, but the discovery urges vendors to update firmware and remove legacy signed components. The issue underscores the need for continuous firmware maintenance and the removal of unused or outdated signed binaries. The researchers recommend that organizations verify the integrity of their firmware and consider disabling legacy UEFI modes to mitigate the risk.

The discovery is a significant security concern for any organization that relies on Secure Boot to protect against boot‑time attacks. It also raises questions about the long‑term viability of signed firmware components that are no longer actively maintained. The vulnerability demonstrates how attackers can leverage seemingly benign, signed binaries to compromise system integrity from the earliest stages of the boot process.

Key changes

  • 11 legacy Microsoft‑signed UEFI apps can bypass Secure Boot
  • Allows execution of untrusted code during system boot
  • Enables deployment of malicious UEFI bootkits
  • Affects most modern firmware systems
  • No current patch released by Microsoft
  • Vulnerability demonstrates firmware signing process weakness
  • Impacts both consumer and enterprise hardware

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting