securitylab_nJuly 15, 2026🇷🇺Translated from Russian

Secure Boot Bypassed for Over a Decade Through Unrevoked Vulnerable Shim Bootloaders, ESET Finds

Secure Boot, one of the primary security mechanisms protecting Windows and Linux systems from early-stage malware, could be bypassed for nearly its entire existence, researchers at ESET have revealed. The flaw remained undetected for more than ten years because Microsoft continued to trust outdated shim bootloader images that contained known vulnerabilities.

The shim components were originally created to extend Secure Boot support to Linux distributions and pre-OS utilities. Microsoft signed these files with its own certificate, allowing UEFI firmware to execute them during the boot process. ESET identified 11 vulnerable shim images; the oldest known sample appeared in 2013, only one year after Secure Boot was introduced.

Although the vulnerabilities in these components had been publicly known for years, Microsoft never added the corresponding hashes or certificates to the UEFI revocation database (dbx). As a result, systems continued to trust the old files, enabling attackers to break the signature verification chain and install persistent bootkits.

The attack required no new exploits. An adversary only needed a copy of one of the still-valid legacy shim files and basic knowledge of the UEFI boot process. Once executed, the compromised shim could disable subsequent signature checks and load malicious code before the operating system itself started.

Because UEFI firmware does not bind a Microsoft-signed shim to any particular operating system, the same vulnerable images could be used against both Linux and Windows machines. After bypassing Secure Boot, attackers could deploy bootkits such as LoJax, MosaicRegressor, CosmicStrand, or BlackLotus, some of which have been linked to nation-state actors.

The affected files were listed by CERT and included shims from Red Hat, openSUSE, Oracle, and third-party vendors such as Finnish company PC-Doctor, which was used in national examination systems. Several of the images predated modern revocation mechanisms like SBAT (Secure Boot Advanced Targeting) and SVN (Security Version Number), and some failed to honor Machine Owner Key deny lists.

Microsoft finally revoked the 11 vulnerable shims in its June security updates after receiving the report from ESET. The company is responsible for maintaining the central trust store for the UEFI ecosystem, yet the incident demonstrates how difficult it remains to track and revoke thousands of signed boot components over time.

Windows 11 Secured-core devices were likely protected by default thanks to additional hardware-backed policies, but general Windows and Linux users are advised to verify that their firmware has received the updated revocation lists via the Linux Vendor Firmware Service or the uefi-dbx-audit script.

Related articles

AntiMalwareVulnerabilities & Exploits

New Windows 11 Bypass Lets Users Skip Internet and Microsoft Account During Setup

A new method has been discovered that allows Windows 11 Home users to complete initial setup without an internet connection or Microsoft account. The technique requires no command-line tools or scripts and was found by enthusiast Bob Pony. During the OOBE process, users simply open the sign-in options and click the Learn more link, which redirects the wizard to local account creation. Previous bypasses such as OOBE\bypassnro and start ms-cxh:localonly have already been blocked by Microsoft. The new approach appears to be an overlooked interface element and works only on the Home edition. Microsoft is expected to close this loophole in a future update as it continues tightening account requirements.

Security NEXTVulnerabilities & Exploits

CISA Adds Four Actively Exploited Vulnerabilities in GitLab, ConnectWise ScreenConnect and JFrog Artifactory to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added four vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaws affect GitLab Community Edition and Enterprise Edition, ConnectWise ScreenConnect, and JFrog Artifactory. CVE-2026-85706 allows unauthenticated path traversal in GitLab’s commit API, enabling arbitrary file reads. CVE-2026-84869 in ScreenConnect permits unauthorized file transfer and execution over active remote sessions. Two additional issues in Artifactory, CVE-2026-42018 and CVE-2026-42016, can lead to token leakage and privilege escalation. Federal agencies have been directed to apply mitigations and investigate potential compromises by specific deadlines.

Security NEXTVulnerabilities & Exploits

Critical Vulnerability in ConnectWise ScreenConnect Enables Unauthorized File Transfers

ConnectWise has disclosed a serious vulnerability in its remote access product ScreenConnect that allows attackers to transfer and execute files from active remote sessions without requiring authorization or host-side confirmation. The flaw, tracked as CVE-2026-84869, impacts both Support and Access session types and carries a CVSS v3.1 base score of 9.9, placing it in the Critical severity category. The company rated the issue as Important in its three-tier scale and assigned it the highest priority of High. Exploitation of the vulnerability has already been confirmed in the wild, increasing the urgency for organizations using the product. ConnectWise published the security advisory on September 8, 2026, urging users to apply available mitigations promptly. The vulnerability stems from improper handling in the file transfer process within the client component.

HabrVulnerabilities & Exploits

Can IDOR Vulnerabilities Be Found Through Static Analysis? New Python Kernel Aims to Answer the Question

A researcher has developed a static analysis module for detecting Insecure Direct Object Reference (IDOR) vulnerabilities in Python web applications. The tool moves beyond simple heuristics by tracking the relationship between user-controlled identifiers, database objects, and authorization checks. It supports Django, Django REST Framework, Flask, and FastAPI, using a custom taint-tracking system called SIAOD to label data origins. Existing approaches such as OpenAPI specifications, broad AST heuristics, Semgrep, and CodeQL were analyzed and found insufficient for capturing the precise semantics of IDOR. Testing on 150 small repositories yielded 48 true positives out of 112 findings, while analysis of 12 million lines of production code from 15 companies produced only five confirmed issues amid hundreds of false positives caused by authorization logic residing outside handler functions. The work demonstrates both the feasibility and current limitations of deterministic static detection for this vulnerability class.