FIRMWARE LAB

UEFI Shell Secure Boot Bypass Inspector

ADVISORY: CERT/CC VU#987231
Hardware & Firmware Policy AMI APTIO
Shell Boot Entry Exposed Embedded shell mapped in BootOrder
NVRAM Variable Lock Protects Boot#### from untrusted edits
Deterministic Verification State
Vulnerability Status: Vulnerable
Bypass Vector: Embedded UEFI Shell Boot Entry
OS Exec Prevented: true
Mitigation Readiness: Action Required: Lock NVRAM variables and disable external shell paths.
Execution Graph: Pre-Boot vs OS Verification STANDBY
Active Vendor
AMI
Security State
BYPASS RISK HIGH
1. SEC / PEI Phase Initialized CPU microcode loaded, Trusted Execution Environment init
AUTHENTICATED
2. DXE Driver Dispatch & Boot Manager BDS evaluates BootOrder and NVRAM variables
NVRAM UNLOCKED
3. Embedded UEFI Shell Invoked Direct execution of arbitrary scripts and binaries prior to OS handoff
BYPASS TRIGGERED
4. OS Bootloader & Secure Boot Bouncer Shim/grubx64.efi signature verification (Never reached)
PREVENTED / SKIPPED
[SEC] Platform Reset Vector @ 0xFFFFFFF0
[PEI] Memory Initialization Completed (16384 MB)
[DXE] Loading DXE Core... VariableStoreProtocol active
[BDS] WARNING: Shell boot option enabled in BootOrder (Boot0001)
[BYPASS] Interactive Shell launched: script overrides active policy!
[EXEC] Running unauthorized binary: fs0:\efi\boot\payload.efi
[SECURITY] Secure Boot signature validation never invoked. OS handoff abandoned.
Mitigation & Audit Control

Validate adherence against CERT/CC VU#987231 advisory recommendations for enterprise firmware deployments.

Disable Embedded Shell in BootOrder Remove Shell entry from BDS menu & factory default list
Enforce VariableLockProtocol on NVRAM Prevent runtime & OS-level modification of Boot#### variables
Apply DBX Revocation List Blacklist known vulnerable firmware binaries & boot shims
TPM PCR[4] Boot Flow Measurement Verify measured boot attestation fails if shell executes
Complies with NIST SP 800-147B and CERT/CC VU#987231
Enjoy this tool? Build your own with Super