VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database…

security

Sources

VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass · TechNews