Vulnerability Management

Widespread Secure Boot bypass threat found in Framework computers

Computer repair concept. Hardware or software error.

Cybernews reports that nearly 200,000 Framework laptops and desktops have signed UEFI shells that could enable Secure Boot evasion.

Inclusion of the 'mm' command within the UEFI shells enables direct read and write to system memory, leading to the eventual bypass of operating system defenses, according to an Eclypsium analysis.

"While this capability is essential for legitimate diagnostics, it's also the perfect tool for bypassing every security control in the system," said Eclypsium researchers.

Such findings follow the discovery of various other Secure Boot bypass methods, including one involving the copy-pasting of firmware code. Multiple bootkits, including BootHole, BlackLotus, and EFILock, have also been used to abuse operating system components and circumvent Secure Boot, with researchers noting the presence of subscription-based UEFI-level anti-cheat evasion tools that exploit Microsoft-signed components.

"The problem isn't their existence it's their implementation, specifically the trust granted via Secure Boot, and the dangerous commands they expose," Eclypsium added.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds