Skip to main content

VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

2 companies named across 6 categories, one of 22 articles referencing Lenovo. Previous coverage: Aviz details its SONiC-based AI networking stack with ONES, OPB and Copilot (Jul 2026).

Companies mentioned

Best suited for

Seniority
Director
Job function
Chief Information Security Officer
Persona
Security Operations Leader
Buyer role
Decision Maker / Budget Holder
Buyer journey
Need to Buy
Adoption curve
Early Majority
Technology maturity
Market Correction
Industry
Information Technology / Software & Services / Cybersecurity / Governance, Risk & Compliance (GRC) & Security Ratings

Our classification, not the publisher's statement. Best suited for, not only for.

Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections. The issue involves abusing UEFI Shell commands that modify memory, enabling arbitrary code execution during the pre-boot phase.

Vendor-signed UEFI Shell applications can be permitted to execute with Secure Boot enabled. On affected systems that trust the vendor certificate in the UEFI Authorized Signature Database (DB) or include the application’s Authenticode hash in DB, an attacker with sufficient access could use direct memory-access capabilities to disable or circumvent Secure Boot enforcement and execute untrusted UEFI code. This behavior is associated with specific UEFI Shell applications exposing commands such as mm (Memory Modify) and interacting with the UEFI environment, which can modify the protected pre-boot state. Researchers from Binarly identified multiple UEFI Shell applications vulnerable to this abuse, and Eclypsium reported some similar signed UEFI shell binaries; neutralization requires adding affected binaries to vendor-specific DBX revocation lists to prevent execution. The impacted applications listed include Acer, Dell, Eurosoft, Framework, Getac, Lenovo, MinisForum, Msi, Seagate, Uniwill, and multiple “Unknown” entries, each with an “mm,dmpstore” vulnerable function and corresponding Authenticode SHA hash and SHA256 file hash values.

This vulnerability impacts systems that trust the compromised vendor certificate within their UEFI Authorized Signature Database (DB) or include the affected application’s Authenticode hash in DB. An attacker with physical access or administrative privileges can leverage these trusted components to bypass Secure Boot and execute arbitrary code during the pre-boot phase. The malicious code can achieve persistent platform compromise, including the loading of unsigned kernel components, while remaining entirely invisible to standard security controls and Endpoint Detection and Response (EDR) solutions.

Apply the latest firmware and software updates from your hardware vendor, expected to replace vulnerable UEFI applications with secure versions. Update and verify UEFI DBX on affected systems to revoke trust in vulnerable binaries or, where necessary, the certificates used to sign them, preventing the affected binaries from executing during boot.

Thanks to Binarly for researching and reporting the vulnerability. Thanks to Eclypsium researchers continued work on UEFI risks from signed applications. This document was written by Vijay Sarvepalli. References provided include a Binarly blog post titled “Signed and dangerous: BYOVD attacks on Secure Boot,” a CERT vulnerability note with identifier 457458, and an Eclypsium blog post titled “Bombshell: The signed backdoor hiding in plain sight on Framework devices.”

Blog post, originally published by Vijay Sarvepalli at kb.cert.org.