Microsoft’s Secure Boot has been broken for a decade and no one had noticed until now



To further complicate the process, including the expiration of the Microsoft certificate that signed the shims, which took place end of last monthIt is not enough to revoke those that ESET identified.

A rogue’s gallery of defective tights

The shims identified by ESET authorize secondary components that are known to be vulnerable to various exploits. The Oracle shim, for example, signs a binary vulnerable to CVE-2015-5381. Smolár said the skill needed to exploit the vulnerability is low. Other vulnerable wedges do not support protections, such as MOK deny list enforcement and SBAT enforcement, both of which took effect after the affected wedge was released. Other identified shims contain vulnerabilities in their own code.

For the sake of brevity, many additional details included in Tuesday’s report are omitted from this article.

A disturbing perspective

As noted, these vulnerable fixes can be used against Windows and Linux machines alike, although probably not against secure-kernel PCs running Windows 11 in its default state. Any Windows user who installed Microsoft’s June batch of updates is no longer vulnerable. Linux users should check the Linux Vendor Firmware Service or consult your dealer. Revocation statuses are available using the audit-uefi-dbx script.

The prospect that attackers have had the means to bypass secure boot for more than a decade through what amounts to hack-by-numbers scripts is not a great endorsement of the mechanism proposed by Microsoft in partnership with hardware manufacturers. As mentioned above, a key factor in this debacle is its complexity.

“This is a solid rebuke to the entire secure boot model,” firmware security expert HD Moore, CEO and founder of runZero, and a long-time critic of Secure Boot, said in an interview. Their complaints include Microsoft being the de facto root of trust for the entire UEFI platform, the inability of protection to scale sufficiently, and the ability for components to start even after top-level certificates expire.

“The end result is a lot of unknown (to everyone but Microsoft) signed items that bypass secure boot (some of which can be used to boot other things) and both have normal security bugs and other bugs that mean they can be used to boot almost anything,” Moore added. “The whole ecosystem is kind of broken and needs a reboot.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *