The Bottom Line: Eleven outdated Microsoft-signed UEFI shims allow attackers to bypass Secure Boot and inject malware during the boot process.
Security researchers have identified eleven older UEFI applications signed by Microsoft that can be exploited to bypass Secure Boot on systems with modern firmware standards. An attacker can use these to execute trusted code during system startup and inject UEFI bootkits.
Cybersecurity researchers have discovered eleven older UEFI applications (Unified Extensible Firmware Interface) with Microsoft signatures that enable a bypass of the Secure Boot mechanism on most systems with modern firmware standards. Secure Boot is a security feature that validates the integrity of the boot process through digital signatures.
An attacker who exploits one of these vulnerable applications can execute trusted code during system startup. This opens the possibility of injecting UEFI bootkits or other malware at runtime – an attack vector that evades operating system security measures and enables persistent control over the system.
For information security professionals, this means critical tracking of outdated firmware components in inventory and verification of whether these signed shims are still present in production environments. Microsoft and the affected Linux distributions should communicate mitigation strategies to provide policies for blocklisting these known vulnerable signatures.
Source: thehackernews.com · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.