New research reveals that decade-old, Microsoft-signed UEFI bootloaders can be leveraged by attackers to bypass Secure Boot and execute persistent bootkits on nearly any UEFI-based system.
Researchers at global digital security leader ESET have uncovered a critical firmware security risk involving 11 old, Microsoft-signed Unified Extensible Firmware Language (UEFI) shim applications. These vulnerabilities allow attackers to bypass UEFI Secure Boot on the vast majority of UEFI-based systems, opening the door for deep-seated bootkits and stealthy malware.
UEFI shim bootloaders serve as essential bridges connecting motherboard firmware to an operating system. However, ESET’s findings show that shim versions 0.9 and below contain decade-old vulnerabilities that can be weaponized against any machine trusting the Microsoft Corporation UEFI CA 2011 third-party certificate authority—regardless of the underlying operating system.

The vulnerable binaries originate from various software packages, including PC diagnostic utilities and older Linux distributions. Crucially, exploitation is not restricted to systems that originally installed these packages. Because attackers can execute a “Bring Your Own Vulnerable Binary” (BYOVB) attack, they can simply transport copies of the unrevoked shims to any target system with the Microsoft third-party certificate enrolled.
“What makes these old shims dangerous is not a novel vulnerability; it’s that no new vulnerability is needed to bypass UEFI Secure Boot,” explains ESET researcher Martin Smolár, who led the discovery. “An attacker needs no complicated exploitation primitives – only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature.”
Over the years, upstream UEFI shim repositories have introduced crucial security improvements. However, many third-party vendors historically compiled custom versions of these older sources and submitted them to Microsoft for signing. Because sufficient attention was not paid to revoking these outdated binaries, they can still be exploited to circumvent modern security mechanisms.
Following ESET’s responsible disclosure to CERT/CC, Microsoft has moved to revoke the vulnerable shims.
- Windows Systems: Should receive automatic updates to block the vulnerable binaries.
- Linux Systems: Updates and revocations are accessible through the Linux Vendor Firmware Service (LVFS).
Organizations are strongly urged to apply the latest UEFI revocations to safeguard their infrastructure against advanced, pre-boot persistence threats.





























