ESET Research: Vulnerable UEFI Shims Undermine Secure Boot
News | 21.07.2026
Old, still-trusted UEFI shim bootloaders open a direct path around Secure Boot — no new exploit required.
UEFI Secure Boot is a foundational trust anchor for modern endpoints, servers, and critical infrastructure. When it fails, attackers gain persistence below the operating system, invisible to most endpoint tools. ESET Research has now disclosed 11 Microsoft-signed UEFI shim bootloaders that let adversaries defeat Secure Boot on the majority of UEFI-based systems — regardless of the installed OS — as long as the Microsoft third-party UEFI certificate is enrolled. For CISOs and IT leaders, this is a firmware-layer risk that must be addressed through revocation updates and layered detection.
What was announced
On July 14, 2026, ESET Research disclosed that 11 old, Microsoft-signed UEFI shim bootloaders (versions 0.9 and below) can be abused to bypass UEFI Secure Boot. An attacker exploiting these binaries can execute untrusted code during system boot and deploy malicious UEFI bootkits or other malware. The affected shims originate from PC-diagnostic tools, Linux distributions, and other UEFI utilities. ESET reported the findings to CERT/CC, and Microsoft has since revoked the vulnerable binaries.
Crucially, exploitation is not limited to systems with the affected software or OS installed. Attackers can bring their own copy of a vulnerable shim to any UEFI system that trusts the Microsoft Corporation UEFI CA 2011 third-party UEFI certificate. Windows 11 Secured-core PCs are expected to have this third-party signing option disabled by default.
What makes these old shims dangerous is not a novel vulnerability; it is that no new vulnerability is needed to bypass UEFI Secure Boot. An attacker needs no complicated exploitation primitives — only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work
Why this matters
For CIOs, CISOs, SOC leads, and procurement teams, firmware-level compromises bypass most EDR and antivirus telemetry and survive OS reinstallation. A successful bootkit deployment can persist across reboots, disk wipes, and even some hardware replacements. Because the vulnerable shims are Microsoft-signed, they are trusted by default on a huge installed base of business laptops, workstations, and servers. Any endpoint hardening strategy that assumes Secure Boot alone is sufficient must now be revisited.
Technical details
- Affected components: 11 Microsoft-signed UEFI shim bootloaders, versions 0.9 and below.
- Attack precondition: Microsoft third-party UEFI CA 2011 certificate enrolled in firmware.
- Impact: execution of untrusted code during boot, enabling UEFI bootkit deployment.
- Scope: any UEFI-based machine trusting the third-party UEFI CA, regardless of installed OS.
- Mitigation for Windows: apply the latest Microsoft UEFI revocations (delivered via Windows Update).
- Mitigation for Linux: updates via the Linux Vendor Firmware Service (LVFS).
- Additional hardening: disable Microsoft third-party UEFI signing where not required; enable Secured-core defaults.
Softprom and ESET
Softprom is the official distributor of ESET. Our team helps enterprises assess firmware-level exposure, deploy ESET endpoint protection with UEFI scanning, and operationalize threat intelligence from ESET Research.
Strengthen your defenses against UEFI bootkits and firmware threats with ESET.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.