Thirty trusted UEFI shells now have published hashes for a Secure Boot bypass.
Physical access or equivalent administrative control is still required, but the signed shell is accepted before it turns off enforcement for an unsigned payload.
UEFI PCs and servers whose Authorized Signature Database trusts one of 30 identified shell binaries or its signing certificate.
Secure Boot bypass and persistent execution of unsigned pre-OS code
The 30-binary inventory turns a known bypass class into something fleets can search for, while revocation remains incomplete and pre-remediation images can still be accepted.
Detail and 3 sources
An attacker places a listed shell, startup.nsh, and an unsigned payload on boot-accessible storage. The trusted shell runs the script, which overwrites the Security Architectural Protocol state checked by LoadImage and causes the payload to execute before operating-system defenses start.
This is not a completed revocation event: older images remain usable, revocation coverage is incomplete, and we do not know whether remediation reaches end-of-life hardware.
- access:physical:device-in-hand
- the attacker holds the device
- Pre-fix images still accepted
- Yes
- Revocation complete
- No
The first two answers assess the disclosed remediation as a whole, including the period where replacement shells shipped before revocation.