HomeSecurityMicrosoft found vulnerabilities in GRUB2, U-Boot, Barebox bootloaders via AI

Microsoft found vulnerabilities in GRUB2, U-Boot, Barebox bootloaders via AI

Microsoft used Security Copilot with artificial intelligence to discover previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders . GRUB2 (GRand Unified Bootloader) is the default bootloader for most Linux distributions, while U-Boot and Barebox are commonly used in embedded and IoT devices .

Microsoft found vulnerabilities in GRUB2, U-Boot, Barebox bootloaders via AI

Through AI Security Copilot, the company discovered eleven vulnerabilities in GRUB2 and nine in U-Boot and Barebox. These bugs affect devices based on UEFI Secure Boot and, if the right conditions are met, attackers can bypass security protections and execute (potentially malicious) code on the device.

See also: NCSC urges immediate patching of Next.js vulnerability

In most cases, local access to devices to exploit vulnerabilities. However, in the past, the BlackLotus bootkit has managed to do so through malware infections.

Especially in the case of GRUB2, the vulnerabilities could be exploited to bypass Secure Boot and install stealthy bootkits or potentially bypass other security mechanisms, such as BitLocker.

Installing such bootkits can give threat actors complete control over the device. They can control the boot process and operating system, compromise additional devices, and perform other malicious activities.

Microsoft says that AI Security Copilot dramatically accelerated the process of discovering vulnerabilities in bootloaders, saving about 1 week of time that would have been required for manual analysis. This success shows that AI can be a game-changer in cybersecurity, especially for detecting zero-day vulnerabilities.

See also: New RESURGE malware exploits Ivanti vulnerability

Microsoft bootloaders vulnerabilities U-Boot GRUB2

The tool was able to detect unknown bugs, but it also provided targeted mitigation recommendations, which could speed up the release of security updates.

Using the findings in the analysis, Microsoft says that Security Copilot identified similar bugs in projects that use shared code with GRUB2, such as U-boot and Barebox.

GRUB2, U-boot, and Barebox released security updates for the vulnerabilities in February 2025, so updating to the latest versions should fix the vulnerabilities.

Microsoft's vulnerability discovery is very important, as bootloaders are a key part of an operating system's booting system. If a hacker exploits a vulnerability at this stage, they can gain control of the system, making the attack very difficult to detect and counter.

See also: WordPress: The vulnerabilities most used by hackers in Q1 2025

It seems that artificial intelligence will be increasingly used to prevent attacks in the future. We have seen AI being used by attackers, but it can also be a powerful weapon for security!

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: www.bleepingcomputer.com


📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS