Back to feed

Researchers disclose UEFI Shell flaw bypassing Secure Boot in AMI, Gigabyte, Insyde, Cisco firmware

1 min
Researchers disclose UEFI Shell flaw bypassing Secure Boot in AMI, Gigabyte, Insyde, Cisco firmware

This digest was compiled by AI from multiple sources — links to the originals are below.

Researchers at CERT/CC disclosed a vulnerability allowing attackers to bypass Secure Boot by launching the UEFI Shell from crafted boot entries. AMI, Gigabyte, Insyde Software, and Cisco have acknowledged affected products. The flaw enables pre-boot code execution that can persist across reboots and OS reinstallation.

Key Facts

  • CERT/CC at Carnegie Mellon University issued an advisory on the UEFI Shell vulnerability.
  • AMI, Gigabyte, Insyde Software, and Cisco have acknowledged affected products.
  • Attackers can craft UEFI boot entries to launch the UEFI Shell even when Secure Boot is enabled.
  • The UEFI Shell provides commands such as dmem and mm to access physical memory.
  • Malicious code executed pre-boot can survive system reboots and OS reinstallation.

Vulnerability Disclosure

CERT/CC within Carnegie Mellon University published an advisory detailing the Secure Boot bypass. The flaw allows attackers with the ability to create additional UEFI boot entries to reference the UEFI Shell even when standard controls prevent its execution. AMI, Gigabyte, Insyde Software, and Cisco have acknowledged affected products.

Technical Impact

The UEFI Shell is a command-line interface embedded in SPI Flash firmware for debugging and diagnostics. It provides commands such as dmem and mm that can access physical memory. Attackers can overwrite Secure Boot-related memory values and run unauthorized code during early boot. Code executed in the pre-boot phase can establish persistent access, loading malicious boot components or kernel-level software.

Persistence and Evasion

Malicious activity in the pre-boot environment is invisible to OS-based security controls and EDR software. The persistence can survive system reboots and, in some cases, reinstallation of the operating system. CERT/CC recommends applying firmware updates and restricting changes to UEFI boot entries.

1 source

Time · lag behind first