Complicating matters further, despite the expiration of the Microsoft certificate that signed the malicious shims last month, this does not negate the threats identified by ESET.
Rogue Gallery of Vulnerable Shims
The shims flagged by ESET enable secondary components that are susceptible to numerous exploits. For instance, Oracle shims are known to sign binaries with vulnerabilities like CVE-2015-5381. According to Smolár, the skill level required to exploit this vulnerability is minimal. Additionally, other vulnerable shims lack critical protections like MOK deny list enforcement or SBAT enforcement—both of which were implemented after these shims were released. Moreover, some identified shims themselves harbor vulnerabilities within their own code.
For a more concise overview, several additional details from Tuesday’s report have been omitted in this article.
Anxious Outlook on Shim Vulnerabilities
As previously noted, these vulnerable shims pose risks to both Windows and Linux systems; however, they may not be exploitable by default against Windows 11 Secure Core PCs. Users who have applied Microsoft’s June updates are no longer at risk. Linux users are advised to verify the status through Linux vendor firmware services or consult their sales representatives. The revocation status can be checked using the uefi-dbx-audit script.
The alarming possibility that attackers have been able to bypass Secure Boot for over a decade—essentially employing “hacking-by-the-numbers” scripts—undermines the security model championed by Microsoft and hardware manufacturers. As previously mentioned, the underlying issue is its inherent complexity.
“This serves as a strong critique of the entire secure boot model,” commented HD Moore, firmware security expert and CEO of runZero, who has long opposed secure boot practices. His concerns include that Microsoft assumes the de facto role of root of trust for the entire UEFI platform, suggesting that existing protections do not scale effectively, and that components remain operational despite the expiration of top-level certificates.
Moore added, “The outcome is a collection of obscure signatures—known only to Microsoft—that can bypass Secure Boot. Some of these signatures have the potential to launch various applications, yet they often contain typical security flaws and errors, enabling the execution of almost anything.” He concluded, “The overall ecosystem appears to be malfunctioning and is in dire need of a reboot.”
Source: arstechnica.com


