Feb. 6, 2024, 4:50 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

On February 2, 2024 details about a new vulnerability being tracked as CVE-2023-40547 was released for shim, a critical piece of software used by most Linux distributions in the boot process to support Secure Boot. Discovered and reported by Bill Demirkapi at Microsoft’s Security Response Center, this particular vulnerability stems from HTTP protocol handling, leading to an out-of-bounds write that can lead to complete system compromise.


What is Shim?


Due to legal issues arising from license incompatibilities, open-source projects …

bill bill demirkapi boot center critical cve demirkapi distributions february linux linux distributions linux systems microsoft new vulnerability piece process real response secure boot security shim software support systems vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Information Systems Security Manager

@ Bank of America | USA, MD, Fort Meade (6910 Cooper Ave)

Security Engineer

@ EY | Bengaluru, KA, IN, 560048