<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx" -->

---
title: 11 unrevoked UEFI shims left Secure Boot bypassable for...
description: ESET researcher Martin Smolár discovered that 11 UEFI shim bootloaders (version 0.9 or earlier) signed by Microsoft were never revoked after vulnerabilities...
canonical: https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: 11 unrevoked UEFI shims left Secure Boot bypassable for over a decade | daily.dev
og:description: ESET researcher Martin Smolár discovered that 11 UEFI shim bootloaders (version 0.9 or earlier) signed by Microsoft were never revoked after vulnerabilities...
og:url: https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx
og:image: https://api.daily.dev/og/posts/vEaodxpZx.png
og:image:alt: 11 unrevoked UEFI shims left Secure Boot bypassable for over a decade
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 11 unrevoked UEFI shims left Secure Boot bypassable for over a decade

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 2 upvotes · 1 comments

## Summary

ESET researcher Martin Smolár discovered that 11 UEFI shim bootloaders (version 0.9 or earlier) signed by Microsoft were never revoked after vulnerabilities were found, leaving Secure Boot bypassable for over a decade. The shims, some dating to 2013, are exploitable via three weaknesses: trust in old GRUB 2 binaries affected by CVE-2015-5281, lack of SBAT revocation support (added only in shim 15.3), and a certificate length mismatch bug (CVE-2026-10797). An attacker can place any of these shims on a USB drive or Windows EFI partition to deploy bootkit malware like BlackLotus, which survives OS reinstalls. Microsoft revoked all 11 binaries in the June 2026 Patch Tuesday DBX update, four months after ESET's February 2026 disclosure. Systems without that update remain vulnerable, and ESET warns additional forgotten signed shims may still exist.

## Content

## What happened

ESET researcher Martin Smolár found 11 Microsoft-signed UEFI shim bootloaders — some dating back to 2013 — that were never revoked after their vulnerabilities became known. Because Secure Boot validates a shim's cryptographic signature rather than anything about the machine it originally shipped on, any of these old binaries can be dropped onto a USB drive or into a Windows EFI partition and used as a launchpad for bootkit malware. No novel exploit required.

The affected shims are version 0.9 or earlier, pulled from products like Red Hat Enterprise Linux 7.2 and CentOS 7.2. They're vulnerable through three distinct weaknesses: they trust old GRUB 2 binaries affected by a 2015 flaw (CVE-2015-5281), they predate the SBAT revocation mechanism introduced in shim 15.3, and a certificate length mismatch bug (CVE-2026-10797) lets attackers slip malicious binaries past signature checks.

## Why this is a bigger deal than a typical vulnerability

Secure Boot has existed for 14 years. These shims have been exploitable for 13 of them. The CMU CERT Coordination Center confirmed the core problem: vulnerable shim versions were simply never added to the UEFI revocation database (DBX), meaning every system that trusted Secure Boot was quietly exposed the entire time.

The practical consequence is nasty. A successful attack installs bootkit malware — like BlackLotus — that runs before the OS loads, survives full OS reinstalls, and persists even after replacing the hard drive. Admin privileges or physical boot access are enough to pull it off.

## The fix and what's still uncertain

Microsoft revoked all 11 binaries via a DBX update in the June 2026 Patch Tuesday, roughly four months after ESET's February disclosure. Systems that haven't applied that cumulative update remain exposed.

ESET's warning is worth taking seriously: more forgotten signed shims may still exist undiscovered. The revocation database is only as good as the auditing behind it, and this episode suggests that auditing has been incomplete for a long time.

## Community discussion

Top comments from developers on daily.dev.

**@franio68** · 0 upvotes

> Microsoft. Again. Linux has been knocking on my door for a long time. Hmmm

## Similar posts on daily.dev

- [Schneier on Security](https://daily.dev/posts/schneier-on-security-gtentyiez) · Schneier on Security · 2 upvotes · 0 comments
- [Windows and Linux users: The deadline to update Secure Boot keys is near](https://daily.dev/posts/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near-nvkg8wx89) · Ars Technica · 35 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"11 unrevoked UEFI shims left Secure Boot bypassable for over a decade","url":"https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx"},"datePublished":"2026-07-15T07:38:40.606Z","dateModified":"2026-07-15T13:06:25.514Z","description":"ESET researcher Martin Smolár discovered that 11 UEFI shim bootloaders (version 0.9 or earlier) signed by Microsoft were never revoked after vulnerabilities...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e1ae5d523df52a9891223970f6af2e1b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e1ae5d523df52a9891223970f6af2e1b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"11 unrevoked UEFI shims left Secure Boot bypassable for over a decade"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/11-unrevoked-uefi-shims-left-secure-boot-bypassable-for-over-a-decade-veaodxpzx","comment":[{"@type":"Comment","text":"Microsoft. Again. Linux has been knocking on my door for a long time. Hmmm","datePublished":"2026-07-15T16:16:07.076Z","dateModified":"2026-07-15T16:17:15.458Z","url":"https://daily.dev/posts/vEaodxpZx#c-cdCneD5DW","author":{"@type":"Person","name":"Francisco Dávila","url":"https://daily.dev/franio68","image":"https://avatars.githubusercontent.com/u/76629453?v=4"}}]}
```

