CVE-2026-8863
CVSS 7.8 HIGH: multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. EPSS 0.1% (1º percentile). Patch Microsoft: 5094123.
Patch disponibile KB5094123 Scarica →
Vulnerabilità · 74 giorni fa
La protezione di Secure Boot si rompe quando una vecchia shim firmata resta ancora recuperabile da qualche parte della catena di trust. Il punto non è solo che il certificato Microsoft esista, ma che ogni shim legacy revocata sia stata davvero esclusa ovunque: se una copia vecchia è ancora raggiungibile, il boot può partire da un artefatto che il firmware considera legittimo e poi passare a loader successivi che ammettono codice non verificato.
ESET ha individuato undici versioni di shim Microsoft-signed, tutte a 0.9 o inferiori, che consentono il bypass di UEFI Secure Boot; Microsoft le ha revocate nel Patch Tuesday del 9 giugno 2026. Le due CVE principali sono CVE-2026-8863 e CVE-2026-10797, e il caso si estende anche a catene che includono GRUB 2 vulnerabile, fino a CVE-2015-5281. La portata reale resta però incerta perché i registri storici di firma sono incompleti.
Per chi usa Secure Boot come confine di fiducia all’avvio, il rischio non è confinato ai sistemi che avevano già quella shim installata: una copia fornita dall’attaccante sull’EFI partition basta a riaprire il varco. La vera unità di misura diventa quindi l’esaustività della revoca e dell’inventario delle shim storiche, non il solo fatto che Secure Boot risulti attivo.
CVSS 7.8 HIGH: multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. EPSS 0.1% (1º percentile). Patch Microsoft: 5094123.
Patch disponibile KB5094123 Scarica →
7 fonti che coprono questa storia
Old UEFI Shims Expose Systems to Secure Boot Bypass
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS.
Forgotten Bootloaders Expose Secure Boot Blind Spot
Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.
Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Eleven old Microsoft-signed UEFI shims could let admin-level attackers bypass Secure Boot and run code before the operating system loads
No one knows how many old shims can still bypass UEFI Secure Boot - Help Net Security
Eleven forgotten Microsoft-signed shims enabled a UEFI Secure Boot bypass on nearly any PC.
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-07-17