ESET Identifies Vulnerabilities in Microsoft-Signed UEFI Shims, Threatening Secure Boot
ESET has reported 11 vulnerabilities in UEFI shim bootloaders signed by Microsoft, allowing attackers to sidestep UEFI Secure Boot. This discovery poses significant risks for government and critical infrastructure, necessitating immediate firmware updates and patching to ensure security. Cybersecurity contractors must prioritize these updates to protect their systems.
Key Signals
- ESET discovers 11 vulnerabilities in UEFI shim bootloaders affecting Microsoft systems
- Urgent need for firmware updates to safeguard against UEFI Secure Boot risks
- Cybersecurity contractors should enhance services for secure boot validation and monitoring
"What makes these old shims dangerous is not a novel vulnerability; its that no new vulnerability is needed to bypass UEFI Secure Boot. An attacker needs no complicated exploitation primitives only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot."
Recent findings from ESET researchers have unveiled 11 serious vulnerabilities within UEFI shim bootloaders signed by Microsoft that present a substantial threat to the integrity of UEFI Secure Boot. This discovery is alarming, particularly for government systems and critical infrastructure that rely on these bootloaders for protection against unauthorized code execution. The vulnerabilities in question are not new; rather, they stem from decade-old coding flaws that can be exploited by leveraging trusted but outdated shim binaries. As a result, contractors and procurement professionals in the cybersecurity sphere must take proactive steps to address this issue to secure sensitive systems.
The UEFI shim bootloader serves as a crucial intermediary between the motherboard's UEFI firmware and the operating system. The vulnerabilities identified exist in shims, specifically those at versions 0.9 and below, which allow attackers to bypass UEFI Secure Boot protections entirely. Unique to this situation is the fact that the attackers can use these unsupported binaries without needing to exploit a new vulnerability. As stated by ESET researcher Martin Smolár, "An attacker needs no complicated exploitation primitives – only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work."
It is important to note that the effects of these vulnerabilities are not limited to systems running the affected software or operating systems. Attackers can easily exploit this by deploying a copy of the vulnerable shims onto any UEFI system that recognizes the Microsoft UEFI CA 2011 third-party certificate authority, regardless of the operating system in use. Therefore, contractors supporting federal projects or operating critical infrastructure must prioritize the application of Microsoft's latest UEFI revocations and coordinate firmware updates with their vendors to shield against these vulnerabilities effectively.
This critical discovery illustrates an essential lesson in the importance of continuous vulnerability assessments, particularly in firmware components that are pivotal to overall system security. Procurement professionals supporting cybersecurity initiatives need to be vigilant and ensure that their clients or agencies are implementing robust update and monitoring practices around UEFI bootloaders to mitigate any real risks associated with these vulnerabilities. As organizations brace for more sophisticated cyber threats, acknowledging and resolving these vulnerabilities is crucial to maintaining the security and trustworthiness of federal systems. Effective remediation strategies will need to include secure boot validation updates as a fundamental part of service offerings for contractors engaged in cybersecurity services.
The vulnerabilities were reported to the CERT Coordination Center, which has taken prompt actions to revoke the affected UEFI applications. This is a critical step in mitigating potential exploitations but emphasizes the need for further action and diligence from agencies and contractors alike. The vulnerabilities pop up in various tools and software packages, which means an extensive review of hardware and firmware update policies across agencies is required to stay ahead of the risks posed by these UEFI shims.
Moving forward, organizations throughout the federal contracting space must focus on fortifying their technology against such simple yet effective exploitations. Ensuring that firmware is up-to-date should be a non-negotiable aspect of any cybersecurity protocol. Regular updates and stringent adherence to security measures will be vital to securing critical infrastructure applications and services that underpin national security.
Agencies
- CERT Coordination Center
Vendors
- Microsoft Corporation
Sources
- ESET Research Uncovers Vulnerabilities in UEFI Shims That Compromise Secure Boot – Arabian ResellerArabian Reseller · Jul 25