PT-2026-50773 · Undefined · Undefined
CVE-2026-10797
·
Publicado
2026-06-18
·
Atualizado
2026-07-16
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
11 forgotten, still-trusted UEFI shims (v0.9 and below) bypass Secure Boot on any system enrolling the Microsoft Corporation UEFI CA 2011 certificate. CVE-2026-8863 and CVE-2026-10797 assigned; revoked in Microsoft's June 9 2026 Patch Tuesday dbx update.
-
The core risk is not a novel bug: any attacker can copy a vulnerable, Microsoft-signed shim to the EFI System Partition of a target machine regardless of its installed OS, pair it with an old GRUB 2 binary, and execute unsigned code at boot, enabling bootkits like BlackLotus, Bootkitty, or HybridPetya. No memory corruption, no ROP chain required.
-
CVE-2026-10797 (shims v0.9 and below): the revocation check and signature verification functions read the signature length from different PE structures. An attacker manipulates the WIN CERTIFICATE length field so dbx and MokListX comparisons run against garbage, silently bypassing certificate-based revocations for any shim-embedded certificate.
-
Pre-v15.3 shims ignore SBAT entirely; pre-v0.9 shims ignore MokListX. An enterprise that revoked a compromised MOK certificate via MokListX is fully exposed if an attacker substitutes one of these old shims, which trusts MokList but skips the denylist.
-
11 PE Authenticode hashes were added to dbx on June 9 2026. Note: the expiration of Microsoft Corporation UEFI CA 2011 on June 27 2026 does NOT revoke trust in binaries it signed; certificate expiry has no effect on Secure Boot verification.
#DFIR Radar
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined