Cybernews reports that nearly 200,000 Framework laptops and desktops have signed UEFI shells that could enable Secure Boot evasion.Inclusion of the 'mm' command within the UEFI shells enables direct read and write to system memory, leading to the eventual bypass of operating system defenses, according to an Eclypsium analysis."While this capability is essential for legitimate diagnostics, it's also the perfect tool for bypassing every security control in the system," said Eclypsium researchers.Such findings follow the discovery of various other Secure Boot bypass methods, including one involving the copy-pasting of firmware code. Multiple bootkits, including BootHole, BlackLotus, and EFILock, have also been used to abuse operating system components and circumvent Secure Boot, with researchers noting the presence of subscription-based UEFI-level anti-cheat evasion tools that exploit Microsoft-signed components."The problem isn't their existence it's their implementation, specifically the trust granted via Secure Boot, and the dangerous commands they expose," Eclypsium added.
Vulnerability Management
Widespread Secure Boot bypass threat found in Framework computers

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



