"Decades-Long Secure Boot Vulnerability Exposed"

"A critical flaw in Microsoft's Secure Boot system, designed to protect Windows and Linux devices from firmware-level attacks, has been revealed to have existed for nearly two-thirds of its 14-year lifespan."

Researchers have uncovered a serious vulnerability in Microsoft's Secure Boot system, which has been present for 13 out of its 14 years of existence. The discovery was made by resear The vulnerability, identified as CVE-2018-7600, was initially discovered in 2018 and was supposed to have been patched by Microsoft. However, the patch was never released due to a complex process of vetting and testing. As a result, the vulnerability remained unaddressed for years, allowing attackers to easily bypass Secure Boot's security features.

Experts say the vulnerability is particularly troublesome because it affects not only Windows but also Linux devices, making it a significant concern for the broader IT industry.

The vulnerability was discovered by researchers using a combination of automated tools and manual testing, and was initially reported to Microsoft in 2019. Despite multiple attempts to get Microsoft to acknowledge and address the issue, the company has been slow to respond, leaving many in the industry wondering why it took so long to fix the problem.

Microsoft has since acknowledged the vulnerability and released a patch, but it has been criticized for its slow response to the issue. The patch was released in 2022, nearly four years after the vulnerability was first discovered.

Source: Schneier on Security