{"id":55293,"date":"2024-02-09T21:06:33","date_gmt":"2024-02-09T21:06:33","guid":{"rendered":"http:\/\/30249a32-e9ff-468d-b811-d1d3420de226"},"modified":"2024-02-09T21:06:33","modified_gmt":"2024-02-09T21:06:33","slug":"shim-vulnerability-exposes-most-linux-systems-to-attack","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/","title":{"rendered":"Shim vulnerability exposes most Linux systems to attack"},"content":{"rendered":"<figure class=\"c-shortcodeImage u-clearfix c-shortcodeImage-large\">\n<div class=\"c-shortcodeImage_imageContainer\">\n<div class=\"c-shortcodeImage_image\"><picture class=\"c-cmsImage c-cmsImage_loaded\"><source media=\"(max-width: 767px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/c7033948b8eb3de62056ef909f51fbdf0afdc036\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=768\" alt=\"keyboard-handgettyimages-512136509\"><source media=\"(max-width: 1023px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/12d93520914a10a63ae0a0e7c1971fa377377028\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1024\" alt=\"keyboard-handgettyimages-512136509\"><source media=\"(max-width: 1440px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\" alt=\"keyboard-handgettyimages-512136509\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\" alt=\"keyboard-handgettyimages-512136509\" width=\"1280\" height=\"959.3600000000001\" fetchpriority=\"low\"><\/picture><\/div>\n<p> <!----><\/div>\n<p> <!----><figcaption> <span class=\"c-shortcodeImage_credit g-outer-spacing-top-xsmall u-block\">Andrew Brookes\/Getty Images<\/span><\/figcaption><\/figure>\n<p>Another day, another potential Linux security problem. This time around, it&#8217;s a critical vulnerability in shim &#8212; the key link between Linux and your computer&#8217;s firmware during boot. Left unrepaired, a network attacker could bypass secure boot and take control of your system.<\/p>\n<p>First things first: The shim in question is not a part of Linux per se. It&#8217;s the bridge between modern PCs and servers&#8217; Unified Extensible Firmware Interface (UEFI) Secure Boot and Linux. Technicalities aside, you must use it to boot Linux, so it&#8217;s a big deal.&nbsp; <\/p>\n<p>Shim exists because Secure Boot, a computer security standard to replace older computers&#8217; BIOS firmware, wouldn&#8217;t work with most&nbsp; Linux distributions when it was introduced in 2012. Secure Boot used &#8212; and still uses &#8212; a Windows-friendly secure key database with no easy way for Linux distros to get it in. Matthew Garrett, a well-known Linux and security developer, created a fix. This was the <a href=\"https:\/\/www.zdnet.com\/article\/shimming-your-way-to-linux-on-windows-8-pcs\/\" rel=\"follow\">shim, a signed boot-loader that can add keys to its own database<\/a>.&nbsp; <\/p>\n<p><strong>Also: <a href=\"https:\/\/www.zdnet.com\/article\/7-things-even-new-linux-users-can-do-to-better-secure-the-os\/\" rel=\"follow\">7 things even new Linux users can do to better secure the OS<\/a><\/strong><\/p>\n<p>Fast forward a dozen years: Microsoft Security Response Center&#8217;s Bill Demirkapi <a href=\"https:\/\/github.com\/rhboot\/shim\/commit\/0226b56513b2b8bd5fd281bce77c40c9bf07c66d\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">found a security hole<\/a> &#8212;&nbsp;<a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2023-40547\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">CVE-2023-40547<\/a>&nbsp;&#8212; a classic buffer overflow. With a buffer overflow, an attacker can break into a system and potentially install the malware of their choice.&nbsp; <\/p>\n<p>Specifically, the vulnerable part of the shim code is the one that deals with systems using HTTP to boot from a central server on a network. Since you live and work in the 21st century and you&#8217;d never boot from a server running insecure HTTP, you have nothing to worry about &#8211; right? <em>Wrong<\/em>. <\/p>\n<p>On Twitter. Demirkapi <a href=\"https:\/\/twitter.com\/BillDemirkapi\/status\/1750626988795039754\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">explained<\/a>: &#8220;A common misconception I&#8217;ve seen is that this only affects you if you use HTTP boot. if that were true, this wouldn&#8217;t be a Critical bug.&#8221; <\/p>\n<p><!----><\/p>\n<p>In short, this vulnerability requires a specific set of conditions to be exploitable. An attacker would need the ability to direct the system to boot from an HTTP source, which could involve compromising a server or executing a man-in-the-middle attack. Then, to exploit it, the attacker would have to overcome several hurdles, such as gaining physical access to the device or administrative control; it&#8217;s not out of the realm of possibility, especially if the attacker has already breached the network perimeter. <\/p>\n<p>So, how bad is it really? As Garrett told&nbsp;<a href=\"https:\/\/twitter.com\/arstechnica?lang=en\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">Ars Technica<\/a>.&nbsp; <\/p>\n<blockquote readability=\"10.931506849315\">\n<p>In theory, this shouldn&#8217;t give an attacker the ability to compromise the firmware itself, but in reality, <a href=\"https:\/\/arstechnica.com\/security\/2024\/02\/critical-vulnerability-affecting-most-linux-distros-allows-for-bootkits\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">it gives them code execution before ExitBootServices<\/a> (the handoff between the firmware still running the hardware and the OS taking over), and that means a much larger attack surface against the firmware &#8212; the usual assumption is that only trusted code is running before ExitBootServices. I think this would still be called a boot kit &#8212; it&#8217;s able to modify the OS bootloader and kernel before execution. But it wouldn&#8217;t be fully persistent (if you wipe the disk it&#8217;d be gone). <\/p>\n<\/blockquote>\n<p>The <a href=\"https:\/\/nvd.nist.gov\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">National Vulnerability Database (NVD)<\/a>, which thinks it&#8217;s awful,&nbsp;<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-40547\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">first assigned<\/a>&nbsp;the vulnerability a near-top rating on the Common Vulnerability Scoring System (CVSS) of 9.8.<\/p>\n<p><strong>Also: <a href=\"https:\/\/www.zdnet.com\/article\/why-sudo-is-so-important-in-linux-and-how-to-use-it\/\" rel=\"follow\">Linux security: What is sudo and why is it so important?<\/a><\/strong><\/p>\n<p><a href=\"https:\/\/www.redhat.com\/en\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">Red Hat<\/a>, which maintains shim, takes a more sensible view. The Linux powerhouse gives <a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2023-40547\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">CVE-2023-40547 an 8.3 score<\/a>&nbsp;&#8212; that&#8217;s still bad, but not awful.&nbsp; <\/p>\n<p>Why so high a score since it&#8217;s hard to pull off? Shim is in essentially all Linux distributions and has been for over a decade. That&#8217;s a lot of potential targets.&nbsp; <\/p>\n<p>To fix it, you&#8217;ll want to <a href=\"https:\/\/github.com\/rhboot\/shim\/releases\/tag\/15.8\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" class=\"c-regularLink\">patch shim in all your Linux systems<\/a>. Or, if you don&#8217;t ever boot from a network, you could just disable the network boot option. That would work, too.&nbsp; <\/p>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This low-level software is the glue that enables Linux to run on Secure Boot PCs, and it has a nasty problem.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-55293","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Shim vulnerability exposes most Linux systems to attack 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Shim vulnerability exposes most Linux systems to attack 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-09T21:06:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Shim vulnerability exposes most Linux systems to attack\",\"datePublished\":\"2024-02-09T21:06:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/\"},\"wordCount\":669,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\\\/2024\\\/02\\\/09\\\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\\\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/\",\"name\":\"Shim vulnerability exposes most Linux systems to attack 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\\\/2024\\\/02\\\/09\\\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\\\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\",\"datePublished\":\"2024-02-09T21:06:33+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\\\/2024\\\/02\\\/09\\\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\\\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\\\/2024\\\/02\\\/09\\\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\\\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/shim-vulnerability-exposes-most-linux-systems-to-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Shim vulnerability exposes most Linux systems to attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Shim vulnerability exposes most Linux systems to attack 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/","og_locale":"en_US","og_type":"article","og_title":"Shim vulnerability exposes most Linux systems to attack 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-02-09T21:06:33+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Shim vulnerability exposes most Linux systems to attack","datePublished":"2024-02-09T21:06:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/"},"wordCount":669,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/","url":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/","name":"Shim vulnerability exposes most Linux systems to attack 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280","datePublished":"2024-02-09T21:06:33+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/38ead7ce95fe3d0ed6aa2a6678e42fcdc40e1760\/2024\/02\/09\/3c96d6c5-f92b-435c-93a0-7a5291c85a69\/keyboard-handgettyimages-512136509.jpg?auto=webp&amp;width=1280"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/shim-vulnerability-exposes-most-linux-systems-to-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Shim vulnerability exposes most Linux systems to attack"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=55293"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55293\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=55293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=55293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=55293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}