search menu icon-carat-right cmu-wordmark

CERT Coordination Center

UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

Vulnerability Note VU#718077

Original Release Date: 2026-09-08 | Last Revised: 2026-09-08

Overview

The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI flash, an attacker with the ability to modify UEFI boot configuration may be able to create multiple boot option entries and bypass controls intended to prevent the UEFI Shell from launching while Secure Boot is enabled. This could allow an attacker to modify the pre-boot environment and execute unauthorized software during system startup.

Description

The Unified Extensible Firmware Interface (UEFI) is a firmware specification that defines the interface between a computing platform's hardware and operating system (OS) during the early boot process before the operating system is loaded. UEFI Secure Boot helps ensure that only trusted and digitally signed software is executed during these early stages of platform initialization.

The TianoCore EDK II project provides an open-source reference implementation of the UEFI and Platform Initialization (PI) specifications. The project includes the UEFI Shell, which provides command-line utilities for debugging, diagnostics, and advanced platform management. Many OEM and Independent BIOS Vendor (IBV) firmware implementations include the UEFI Shell in SPI flash for service and support purposes. Because the shell executes in the pre-boot environment, it provides powerful commands such as dmem (display memory) and mm (memory modify) that can access physical memory. Many implementations include a boot entry for the UEFI Shell but remove or suppress it when Secure Boot is enabled to reduce the risk of misuse.

A vulnerability disclosed by Eclypsium researcher Stas Lyakhov details a technique in which an attacker with the ability to create additional UEFI boot entries can reference the UEFI Shell even when standard controls are implemented to prevent its execution. An attacker could then exploit the UEFI Shell and its startup scripting capabilities to modify the pre-boot environment, including overwriting Secure Boot-related memory values, and execute unauthorized code during the early boot process.

Impact

An attacker capable of modifying UEFI boot entries may be able to circumvent intended Secure Boot protections and execute arbitrary code before the operating system loads. Code executed during the pre-boot phase may establish persistent access, including the ability to load malicious boot components or kernel-level software that can survive both system reboots and, in some cases, reinstallation of the operating system. Such activity may also reduce the effectiveness of OS-based security controls and endpoint detection and response (EDR) solutions.

Solution

Apply a Patch

Please see the Vendor Information section for responses from vendors that have released updates addressing this issue. Updating UEFI firmware may require OEM-specific tools and deployment processes, as firmware updates are often managed separately from operating system patch management. Follow the guidance provided by your platform vendor when applying firmware updates.

Recommendations for Enterprises

Organizations should review Secure Boot configuration and platform security policies to help prevent or detect unauthorized modifications to UEFI boot entries. Changes to boot configuration should be monitored and audited where possible. Enterprises that use independent endpoint management solutions should consult their OEM vendors for guidance on integrating UEFI firmware updates into their existing firmware lifecycle and patch management processes.

Acknowledgements

Thanks to Stas Lyakhov from Eclypsium for reporting this vulnerability. This document was written by Vijay Sarvepalli.

Vendor Information

718077
 

American Megatrends Incorporated (AMI) Affected

Notified:  2026-04-08 Updated: 2026-09-08

Statement Date:   April 09, 2026

CVE-2026-20293 Unknown
CVE-2026-33197 Affected
CVE-2026-6485 Unknown

Vendor Statement

AMI is affected by this issue.

Cisco Affected

Notified:  2026-04-08 Updated: 2026-09-08

Statement Date:   September 07, 2026

CVE-2026-20293 Affected
Vendor Statement:
Cisco UCS Servers and UCS-based appliances are affected by a variation of this UEFI Shell issue. Cisco has assigned CVE-2026-20293 and published a security advisory for the issue. Refer to the security advisory for additional details: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
References:
CVE-2026-33197 Not Affected
CVE-2026-6485 Not Affected

Vendor Statement

Cisco UCS Servers and UCS-based appliances are affected by a variation of this UEFI Shell issue. Cisco has assigned CVE-2026-20293 and published a security advisory for the issue. Refer to the security advisory for additional details: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Other Cisco products do not rely on UEFI Secure Boot as part of their hardware chain of trust.

GIGABYTE Affected

Notified:  2026-04-08 Updated: 2026-09-08

Statement Date:   July 08, 2026

CVE-2026-20293 Unknown
CVE-2026-33197 Affected
CVE-2026-6485 Unknown

Vendor Statement

Confirmed vulnerability in AMI Aptio UEFI BDS module. A logic error in the Shell boot option removal process allows an attacker with root privileges to create multiple boot entries, bypassing the Secure Boot check and gaining access to the UEFI Shell. This enables arbitrary physical memory read/write, leading to a full Secure Boot bypass.

Solution Implementation: Integrating the security patch provided by AMI into the BIOS build pipeline.
Verification: Verified the fix by attempting to create redundant Shell boot options; confirmed that the updated BDS module now removes all matching entries.
Deployment: BIOS update scheduled for public release before 2026-07-14.

Insyde Software Corporation Affected

Notified:  2026-04-08 Updated: 2026-09-08

Statement Date:   July 09, 2026

CVE-2026-20293 Unknown
CVE-2026-33197 Not Affected
CVE-2026-6485 Affected

Vendor Statement

Insyde believes this issue is based on a vulnerability in the upstream TianoCore codebase. We believe most of our customers and the majority of devices shipping with Insyde BIOS are not affected because they do not include the shell in the system code areas that are approved to execute without being signed during Secure Boot. However, there are a subset of customers that have chosen to include shell for their own reasons and may be affected.

The vulnerabiity is tracking by CVE-2026-6485 which is created by Insyde.
CVSS Score: 8.2 (serious)
CVSS Vector string: 3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Public date is set on July 8 2026.

Intel Not Affected

Notified:  2026-04-08 Updated: 2026-09-08

Statement Date:   August 07, 2026

CVE-2026-20293 Unknown
CVE-2026-33197 Not Affected
CVE-2026-6485 Not Affected

Vendor Statement

We have not received a statement from the vendor.

Phoenix Technologies Not Affected

Notified:  2026-04-08 Updated: 2026-09-08

Statement Date:   April 20, 2026

CVE-2026-20293 Unknown
CVE-2026-33197 Not Affected
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Acer Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Amazon Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Aruba Networks Unknown

Notified:  2026-07-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

ASUSTeK Computer Inc. Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Dell Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fsas Technologies Europe Unknown

Notified:  2026-04-21 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Fujitsu HQ Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

GETAC Inc. Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Google Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Hewlett Packard Enterprise Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

HP Inc. Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Lenovo Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Microsoft Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Star Labs Online Limited Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Supermicro Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

Toshiba Corporation Unknown

Notified:  2026-04-08 Updated: 2026-09-08

CVE-2026-20293 Unknown
CVE-2026-33197 Unknown
CVE-2026-6485 Unknown

Vendor Statement

We have not received a statement from the vendor.

View all 22 vendors View less vendors


Other Information

CVE IDs: CVE-2026-20293 CVE-2026-33197 CVE-2026-6485
API URL: VINCE JSON | CSAF
Date Public: 2026-09-08
Date First Published: 2026-09-08
Date Last Updated: 2026-09-08 15:05 UTC
Document Revision: 1

Sponsored by CISA.