Executive brief
Multiple vendors use a specialized bootloader component called 'shim' to allow their software to start securely on modern computers. This vulnerability allows an attacker with administrative access to use older, insecure versions of this component to bypass 'Secure Boot' protections. If successful, an attacker could install persistent malware that starts before the operating system, making it nearly impossible for standard antivirus software to detect or remove. To fix this, Microsoft is updating a global 'blocklist' to prevent these specific insecure versions from running.
Technical details
Multiple vendor-specific forks of the UEFI 'shim' bootloader (primarily version 0.9 and earlier) fail to properly enforce Secure Boot Advanced Targeting (SBAT) or lack necessary security patches from the upstream project. An attacker with administrative privileges or physical access can perform a 'Bring Your Own Vulnerable Driver' (BYOVD) style attack by replacing the legitimate bootloader with one of these signed but vulnerable versions. This allows for the execution of arbitrary, unsigned code during the early boot phase before the operating system initializes. Such an exploit bypasses Secure Boot protections and can lead to the installation of bootkits that evade EDR and OS-level security controls. Mitigation involves updating the UEFI Forbidden Signature Database (DBX) via Microsoft-signed updates to revoke the affected authenticode signatures.
Affected products
- Spyrus WTGCreator 4.2
- Baramundi Management Suite up to 2024R1
- WhiteCanyon WipeDrive 8.0.0 through 8.1.3
- Finland Matriculation Exam Board Abitti 1 1.0.0
- NTC IT ROSA ROSA Linux R9, R10
- PC-Doctor PC-Doctor Service Center 15, 16
- RedHat Enterprise Linux 7.2
- Oracle Oracle Linux 7.2
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory