VU#718077: UEFI Shell module e... Note

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

The UEFI Shell, when present in firmware, can be exploited to bypass Secure Boot protections. This program offers raw memory access capabilities, which could be abused by attackers. If an attacker can modify UEFI boot configuration, they might create new boot entries to launch the UEFI Shell. This bypasses intended controls that prevent its execution with Secure Boot enabled. The shell's powerful commands like dmem and mm allow direct physical memory access. Attackers could then modify the pre-boot environment, including Secure Boot memory values. This enables the execution of unauthorized software during system startup. The impact is significant, allowing for persistent access and undermining OS security. Applying firmware patches is the primary solution to address this vulnerability. Enterprises should also review Secure Boot configurations and monitor for unauthorized boot entry modifications.