← Back
SiTech Team⏱️ 1 წთ. საკითხავი

Microsoft's Secure Boot Has Been Broken for a Decade — And No One Noticed Until Now

Microsoft's Secure Boot Has Been Broken for a Decade — And No One Noticed Until Now

Microsoft's Secure Boot security mechanism has been vulnerable for a decade, allowing attackers to inject malicious code during system boot without detection.

Microsoft's Secure Boot Has Been Broken for a Decade

ESET researchers discovered that Microsoft's Secure Boot has been trivially bypassable for approximately 13 of its 14-year existence. The vulnerability stems from 11 unrevoked boot shims — small software components that bridge boot loaders — that attackers can exploit to inject malicious code during system startup.

Technical Details: The BXEL BYPASS Technique

The bypass technique, called BXEL BYPASS, exploits unrevoked third-party boot loader components signed by Microsoft's own certificate authority. These components are trusted by Secure Boot but contain vulnerabilities that allow attackers to bypass the security chain entirely.

Implications and Microsoft's Response

Microsoft is working on SBAT (Secure Boot Advanced Targeting) and SVN (Security Version Number) updates to address the vulnerability.

📖 Source