Skip to content
Vulnerable UEFI shims allow decade

Vulnerable UEFI shims allow decade

Feeds.4Sysops •IT News • July 15, 2026

ESET researchers have identified 11 vulnerable UEFI shim bootloaders that allow attackers to bypass Secure Boot on nearly any UEFI-based system. These shims, some dating back to 2013, remained signed by Microsoft despite containing critical flaws or authorizing vulnerable secondary components. Because these binaries were never revoked, attackers can use them to execute untrusted code and deploy persistent bootkits like BlackLotus or BootKitty. Source

Extracted Entities

Attack Types (1)

Platforms (1)