VU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypass
2026-06-18T20:52:13Z•73137710a6992850c3cf6b459974982916015254d88070beb2289ae6661d3d4b
AESBYOVDChrome extensionDBXHaskellIOCTLMicrosoftNULL dereferenceNameConstraintsSecure BootSecurlySignalRGBTLSUEFIVoLTE','IMS','IPsec','SIP integrity','Verizon','Appsmith','XSS',WindowsX.509bootloadercrypton-x509-validationimproper access controlkernel driverplaintext keysshimweak encryption
What happened
This document aggregates multiple CERT/CC vulnerability advisories disclosed June 2026. Notable issues include: vendor-signed UEFI applications and Microsoft-signed shim bootloaders vulnerable to Secure Boot bypass via BYOVD techniques (requiring DBX/forbidden-signature updates to revoke affected binaries); a SignalRGB kernel driver (SignalIo.sys) with overly-permissive device ACLs and unsafe IOCTL handlers (CVE-2026-8049, CVE-2026-8050) allowing local users to access privileged IOCTLs and trigger kernel crashes; crypton-x509-validation Haskell libraries that fail to enforce X.509 NameContrai
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 73137710a6992850c3cf6b459974982916015254d88070beb2289ae6661d3d4b
- Enrichment time
- 2026-06-18T20:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.