Post #4000830
2026-07-22 01:24 UTC
> Microsoft’s digitally signed UEFI bootloader for Windows is the sole anchor of trust on Windows machines. For a component to load during the boot process, the certificate must explicitly sign all other code executed during bootup.
> Shims work differently. They’re a secondary trust anchor, and they’re signed by Microsoft using one of its other UEFI certificates. From there, a certificate belonging to the motherboard or software maker that is embedded into the shim authorizes all software that’s subsequently loaded.
> When vulnerabilities are found in shims, Microsoft revokes them. In the case of the 11 shims, the company failed to do so, in some cases for more than a decade. The company finally revoked them in its regular monthly patch release in June, after ESET brought them to CERT’s and Microsoft’s attention.
anyway hot take but this was always way too much bullshit for dealing with vulns that require physical access to the machine, just leave in front of your door some very "well-loved" chew toys and a dog bowl with "KILLER" printed on it, ezpz
RE: https://infosec.exchange/@patrickcmiller/116960848819652400
Replies (0)
No replies.