# UEFI Shell Flaw Lets Attackers Bypass Secure Boot

Published: 2026-09-22 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/2f15b748-aaf8-59d3-8949-6d9ac901dfcd/uefi-shell-flaw-lets-attackers-bypass-secure-boot

> Vendor-signed UEFI Shell apps expose memory-modify commands that let attackers with device access disable Secure Boot and run unsigned pre-boot code.

CERT/CC has published VU#738147 describing a class of vulnerabilities in vendor-signed UEFI Shell implementations. Because these Shells are cryptographically signed by OEMs and thus trusted by Secure Boot, an attacker who can launch one can abuse built-in memory-manipulation commands (such as 'mm') to directly modify protected pre-boot memory, disable Secure Boot enforcement, and load untrusted UEFI code. Researchers at Binarly identified multiple affected Shell binaries, with Eclypsium independently reporting related signed UEFI shell binaries exposing similarly high-privileged capabilities.

The practical impact is severe for affected systems: an attacker with physical access or administrative privileges can execute arbitrary code before the OS and any EDR/security agents initialize, enabling persistent, stealthy compromise of the platform including loading of unsigned kernel components. This activity would be invisible to standard endpoint security tooling since it occurs entirely in the pre-boot phase.

No CVE identifiers or in-the-wild exploitation are cited in this advisory; the issue is a design/implementation risk in trusted UEFI Shell tooling rather than a currently exploited campaign. CERT/CC recommends applying firmware/software updates from hardware vendors that replace vulnerable UEFI Shell applications, and updating/verifying the UEFI DBX revocation list to block execution of the vulnerable binaries or their signing certificates.

Source reporting: https://kb.cert.org/vuls/id/738147

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2f15b748-aaf8-59d3-8949-6d9ac901dfcd/uefi-shell-flaw-lets-attackers-bypass-secure-boot.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
