11개의 오래된 Microsoft 서명 Linux UEFI 셔임이 보안 부팅을 우회할 수 있는 취약점 발견.
사이버 보안 연구자들은 오래된 11개의 Microsoft 서명 UEFI 애플리케이션에서 보안 부팅을 우회할 수 있는 취약점을 발견했습니다. 공격자는 이러한 취약점을 이용해 시스템 부팅 중 신뢰되지 않는 코드를 실행할 수 있으며, 이로 인해 악성 UEFI 부트킷이나 다른 맬웨어의 배포가 가능해집니다. 이 문제는 최신 펌웨어 표준을 사용하는 대부분의 시스템에 영향을 미칩니다.
11 old Microsoft-signed Linux UEFI shims may allow attackers to bypass Secure Boot.
Cybersecurity researchers have discovered 11 old Microsoft-signed UEFI applications that could allow bypassing Secure Boot. An attacker exploiting these vulnerabilities can execute untrusted code during system boot, enabling the deployment of malicious UEFI bootkits or other malware. This issue affects most systems using the modern firmware standard.