{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/738147#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nVendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database (DB), an attacker with sufficient access could use the application’s direct memory-access capabilities to disable or circumvent Secure Boot enforcement and execute untrusted UEFI code. To mitigate this risk, system administrators should apply available firmware and software updates from affected hardware vendors.\r\n\r\n### Description\r\nThe Unified Extensible Firmware Interface ([UEFI](https://uefi.org)) standard defines the firmware architecture used to initialize hardware and transfer control to modern operating systems during system startup. On systems with Secure Boot enabled, UEFI applications and drivers must be cryptographically signed and verified before their execution. Trust for these signatures is managed through several databases, including the Authorized Signature Database (DB), which commonly contains certificates from original equipment manufacturer (OEM) vendors, operating system authorities, and other supply-chain partners in the UEFI ecosystem. \r\n\r\nThere are multiple implementations of the UEFI Shell, and OEM vendors typically sign the implementation that they distribute. Some UEFI Shell implementations expose built-in capabilities for directly manipulating system memory and interacting with the UEFI environment. Because the Shell is vendor-signed and therefore permitted to execute with Secure Boot enabled, an attacker who can launch a vulnerable Shell can use these capabilities to modify the protected pre-boot state and potentially load or execute untrusted UEFI code. This creates a security boundary violation: Secure Boot permits execution of the signed Shell, while the Shell itself provides the primitives necessary to circumvent the integrity protections Secure Boot is intended to enforce. As a result, an attacker can potentially compromise the pre-boot environment despite Secure Boot being enabled.\r\n\r\nResearchers from Binarly identified multiple UEFI Shell applications vulnerable to this type of abuse. Note that [Eclypsium](https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/) has also identified and reported some such signed UEFI shell binaries that expose high-privileged capabilities that can be used to bypass Secure Boot. To neutralize the risk, the affected binaries will need to be added to vendor-specific DBX revocation lists to prevent them from executing on the target systems.\r\n\r\n<table>\r\n\t<thead><tr> <th>Impacted UEFI Applications<br>\r\n\t\t[Vendor, Application and vulnerable function<br>\r\n\t\tAuthenticode SHA hash<br>\r\n\t\tSHA256 file hash]<br>\r\n\t\t</th></tr>\r\n  </thead>\r\n  <tbody>\r\n <tr><td><pre> Acer `UEFI shell` mm,dmpstore\r\n 805f72afd179fe67ceee14c76f92c8f76cad23130fa075d1d5678e242a0d3d52 \r\n f52b8dbffaa9b57910b3c369c384f7ccfe8d696e05e7a8a7f0da0db5540949c2 </pre></td></tr>\r\n<tr><td><pre> Acer `UEFI shell` mm,dmpstore\r\n b0af2158f11535d8458b8497a35e96d5afc76e43825f255d2d6aa2da74bad883 \r\n b3a999b7fad3c8cfeff88ab8b29d261b241689c857e13414a9ae0e9f84a10a5f </pre></td></tr>\r\n<tr><td><pre> Acer `UEFI shell` mm,dmpstore\r\n a249bd3044e9aa5d4e2dfa9f94b0ffa437f4ebf3f39d57c9f276b3b9988b2b0b \r\n 77a36a8f035dfb1fdf5170f396e29a8b3e4b93558317a51eafd5be9c5ead5ef9 </pre></td></tr>\r\n<tr><td><pre> Acer `UEFI shell` mm,dmpstore\r\n 6ce33e23b21bfa1ce143fdadf55d00340a9fa3215dd73e31fa6307d5733b8841 \r\n 77019c81bdc1accbd0c99b20b12edcd578dabc4cac4fa66934465f20c1c0aa2c </pre></td></tr>\r\n<tr><td><pre> Acer `UEFI shell` mm,dmpstore\r\n ad30615c1ad7da2e47dcf28a571dc62b9c034c6ade434de8daa35965062f3a7f \r\n c0194c555db9f5f7080c3344db028f44af522bac63c13d764ff416ac244e3c08 </pre></td></tr>\r\n<tr><td><pre> Acer `UEFI shell` mm,dmpstore\r\n b0af2158f11535d8458b8497a35e96d5afc76e43825f255d2d6aa2da74bad883 \r\n b2e0afb2844241479db7d19398c837049fb4c7f08560963d616b3c95b1d382e2 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n 2bfbec41b536b248a3e0a28dddfbcd57f774f03b72028cec91def28b2dcffc2f </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n 5cdf3d75c0ec0800b9692aedef19527f06eb4a16fdda586f5527350e2f6a40ad </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n 6ccd1ee8b067d02c083e73a0c2e18712d55b78bd99fec392daf702a147ce6d41 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n a632de93bfd10d89326db2171673bd246cd6533dcdf8e5f6de85949855695e78 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 113a80eac88190d96832cd50c9ea8de3bd6e08d8bcae2e6cea738eb73f64c5d7 \r\n d2ed7a747c5b3e5c83319e5d186ec602918fbf0651d059699a3c68f609d25cf2 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n ec23a874c3c0e852becc8fa4010c60e5f8922fe671f5351cf8a976da59a01f86 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n f75456cd23e492a078b3a81ffbbe262a1511ac9480c4f397e3d4be3b4ce5a455 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 113a80eac88190d96832cd50c9ea8de3bd6e08d8bcae2e6cea738eb73f64c5d7 \r\n f89cdf53d55d70fea31723f52d6b816937aebe2a2212ddcde7e3732e39c1fbfe </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n 3789ca5b6ccd21a528374f0fb85958516966db9331ca68923577352b0a4b45b7 \r\n fb68dfe907b99c23e97f98518d5e1079312d3981df036bb64d4682fe6fff83b5 </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n b0af2158f11535d8458b8497a35e96d5afc76e43825f255d2d6aa2da74bad883 \r\n 20cca70af9e3b4e5640d52840c84a1968d5be6ca881b393bc236f8d349c225ce </pre></td></tr>\r\n<tr><td><pre> Dell `UEFI shell` mm,dmpstore\r\n b0af2158f11535d8458b8497a35e96d5afc76e43825f255d2d6aa2da74bad883 \r\n d4e7b11a30edd1f89c4fa1664eff98907202f15bc59c2cdfddf345a09ffbb1d4 </pre></td></tr>\r\n<tr><td><pre> Eurosoft `UEFI shell` mm,dmpstore\r\n e9d873cbcede3634e0a4b3644b51e1c8a0a048272992c738513ebc96cd3e3360 \r\n 1e918f170a796b4b0b1400bb9bdae75be1cf86705c2d0fc8fb9dd0c5016b933b </pre></td></tr>\r\n<tr><td><pre> Framework `UEFI shell` mm,dmpstore\r\n 2944da098861619e21b522a642235bb2ec189ff20ef96e100b2ffdd9a39c3416 \r\n 51401e93b940dec1a4391303fb6e390194b90113a8f7da6e711253c82a02b8e4 </pre></td></tr>\r\n<tr><td><pre> Framework `UEFI shell` mm,dmpstore\r\n 2944da098861619e21b522a642235bb2ec189ff20ef96e100b2ffdd9a39c3416 \r\n 7e1dbf3e72b8c3c4967364f49da0cd5e3c09d921086d60ac2a493b55818cd7cf </pre></td></tr>\r\n<tr><td><pre> Framework `UEFI shell` mm,dmpstore\r\n 665b26ad26c1d739720a2793acaefbd8b6c16a599b48dcdbf594640522744483 \r\n 0e03ff927005c70636273a4b9287683a821082f952dc7c9beda1a4fc911dddce </pre></td></tr>\r\n<tr><td><pre> Getac `UEFI shell` mm,dmpstore\r\n 09d895bb03bdac3188ef61b09ab72b99492cfd0b785cbc3eb2eb75657a2f9fa0 \r\n 380a387b53a0ca586fe32eb1459b036f5dc178b26b2b0ec618c598eb4714d1fe </pre></td></tr>\r\n<tr><td><pre> Lenovo `UEFI shell` mm,dmpstore\r\n b0af2158f11535d8458b8497a35e96d5afc76e43825f255d2d6aa2da74bad883 \r\n 1f2c450bbf287e35747561723079c166aed3eddfc509b26c18dd8e19417f1838 </pre></td></tr>\r\n<tr><td><pre> MinisForum `UEFI shell` mm,dmpstore\r\n 5e7b3650103fb1c15e610e2381351d9b36546f260284535ed5774adf7532f633 \r\n 9de8a0194052063ce541b34fbd451071ea3051914fc234b6d691d006f0a0f994 </pre></td></tr>\r\n<tr><td><pre> Msi `UEFI shell` mm,dmpstore\r\n 61ee9a23c366a102ceb34c78af7816413769791658cdb668b02cb81ec94f7c70 \r\n da5f4aa2008e6e26c3553b3dee4cf835ceac88820658693704cea35f62733ce3 </pre></td></tr>\r\n<tr><td><pre> Seagate `UEFI shell` mm,dmpstore\r\n 665b26ad26c1d739720a2793acaefbd8b6c16a599b48dcdbf594640522744483 \r\n 53d87f3b7729fe82b47606a85e606c30d2bb61d3da3f01caef17eb7164bca261 </pre></td></tr>\r\n<tr><td><pre> Uniwill `UEFI shell` mm,dmpstore\r\n 55682bec887134a2ccaa2cd5458cd3fe6395ea93bb88c9dc541806428b14fc66 \r\n d4f05110f4bb55677426067db88f61595dc1831659ba43a5770268b73d4eb479 </pre></td></tr>\r\n<tr><td><pre> Unknown `UEFI shell` mm,dmpstore\r\n 044f80d53ecea7dc108bbf54a89f431d22aa4ebd9b43da3a2abba75bede8b431 \r\n 67bf47b637bff078e6eae9afbae26b82c701739ae7fcd8e7d282b1f2901f9634 </pre></td></tr>\r\n<tr><td><pre> Unknown `UEFI shell` mm,dmpstore\r\n 81da15d6acdfb7868ecea44d41c869c2295603af9a44a2d106d4c0e57d669087 \r\n 8e61f24a72c3138bde4b63766ceee1ce1a70a00046cc6867c61520084d884346 </pre></td></tr>\r\n<tr><td><pre> Unknown `UEFI shell` mm,dmpstore\r\n 81da15d6acdfb7868ecea44d41c869c2295603af9a44a2d106d4c0e57d669087 \r\n 88fbb6425f43eb54194dbb607141e65adc2d1e7e0d33b6bfe762504547024942 </pre></td></tr>\r\n\t</tbody></table>\r\n\r\n### Impact\r\nThis vulnerability impacts systems that trust the compromised vendor certificate within their UEFI Authorized Signature Database (DB) or those that include the affected application’s Authenticode hash in the DB. An attacker with physical access or administrative privileges can leverage these trusted components to bypass Secure Boot and execute arbitrary code during the pre-boot phase. Because this execution occurs before the operating system and endpoint security products initialize, the malicious code can achieve persistent platform compromise, including the loading of unsigned kernel components, while remaining entirely invisible to standard security controls and Endpoint Detection and Response (EDR) solutions.\r\n\r\n\r\n### Solution\r\nApply the latest firmware and software updates from your hardware vendor. These updates are expected to replace vulnerable UEFI applications with secure versions. Update and verify the [UEFI DBX ](https://media.defense.gov/2025/Dec/11/2003841096/-1/-1/0/CSI_UEFI_SECURE_BOOT.PDF)  on the affected systems to revoke trust in vulnerable binaries or, where necessary, the certificates used to sign them, preventing the affected binaries from executing during boot.\r\n\r\n\r\n### Acknowledgements\r\nThanks to Binarly for researching and reporting this vulnerability. Thanks to Eclypsium researchers continued work on UEFI risks from such signed applications. This document was written by Vijay Sarvepalli.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/738147"},{"url":"https://www.binarly.io/blog/signed-and-dangerous-byovd-attacks-on-secure-boot","summary":"https://www.binarly.io/blog/signed-and-dangerous-byovd-attacks-on-secure-boot"},{"url":"https://kb.cert.org/vuls/id/457458","summary":"https://kb.cert.org/vuls/id/457458"},{"url":"https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/","summary":"https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/"}],"title":"Vendor-signed UEFI Shell applications allow Secure Boot bypass","tracking":{"current_release_date":"2026-09-22T18:13:12+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.49"}},"id":"VU#738147","initial_release_date":"2026-09-22 18:13:12.386429+00:00","revision_history":[{"date":"2026-09-22T18:13:12+00:00","number":"1.20260922181312.1","summary":"Released on 2026-09-22T18:13:12+00:00"}],"status":"final","version":"1.20260922181312.1"}},"vulnerabilities":[{"title":"Multiple UEFI applications that were digitally signed by various UEFI supply-chain stakeholders were found to be vulnerable to SecureBoot bypass, allowing either UEFI Shell, grub boot loader.","notes":[{"category":"summary","text":"Multiple UEFI applications that were digitally signed by various UEFI supply-chain stakeholders were found to be vulnerable to SecureBoot bypass, allowing either UEFI Shell, grub boot loader. The UEFI shell or third-party applications allows for loading of arbitrary commands or code to be run, irrespective of SecureBoot settings."}],"ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#738147"}],"product_status":{"known_not_affected":["CSAFPID-c2de9a7c-b6c5-11f1-a571-0affd586302f","CSAFPID-c2decb1e-b6c5-11f1-a571-0affd586302f"]}}],"product_tree":{"branches":[{"category":"vendor","name":"GIGABYTE","product":{"name":"GIGABYTE Products","product_id":"CSAFPID-c2de9a7c-b6c5-11f1-a571-0affd586302f"}},{"category":"vendor","name":"Phoenix Technologies","product":{"name":"Phoenix Technologies Products","product_id":"CSAFPID-c2decb1e-b6c5-11f1-a571-0affd586302f"}}]}}