What is the EFI file format?
A .efi file is a system file used by computer systems and devices based on x86-64 and ARM-based hardware. An .efi file contains executable code that runs between the firmware and operating system levels - technically it is a PE32+ Portable Executable image with a UEFI-specific subsystem value rather than a standard Windows subsystem.
Usage of .efi files
.efi system files are used during the system boot process, for staging firmware updates, and running pre-boot programs. .efi files allow the system to hand off pre-boot processes to a controlled environment. Common examples include bootmgfw.efi (Windows Boot Manager), grubx64.efi (GRUB bootloader for Linux), and shimx64.efi (Secure Boot shim). Sometimes .efi files are included in firmware update packages and loaded during the boot process. All .efi binaries must reside on the EFI System Partition (ESP) - a FAT32 volume on a GPT-partitioned disk that firmware can access before any OS driver loads.
EFI and the UEFI specification
The EFI standard was initially developed by Intel. EFI was later updated and became known as UEFI (Unified Extensible Firmware Interface), which has replaced the legacy Basic Input/Output System (BIOS) on virtually all modern PCs and servers. The UEFI Forum, an industry consortium, now maintains the specification.
Security & safety
RISK: MEDIUMAn .efi is executable code that runs at a very privileged moment - before the OS, with full firmware access - so a MALICIOUS .efi (a "bootkit") can be dangerous and persistent. Modern PCs mitigate this with UEFI Secure Boot, which refuses to run .efi binaries that aren't signed by a trusted key. Practical guidance: never place or run an unknown .efi in your EFI System Partition or boot from an untrusted .efi; keep Secure Boot enabled unless you have a specific reason not to. The opposite risk is just as real: deleting or renaming legitimate .efi files in the ESP (e.g. bootmgfw.efi, grubx64.efi) can make the machine unbootable - leave them alone unless you're deliberately repairing the bootloader.
Format details
in a nutshell- Adobe Encapsulated/embedded font or HP printer firmware blobs - A few unrelated products have historically used .efi for internal data; on a PC almost every .efi you meet is a UEFI boot binary.
Programs that open EFI files
Technical details
deep spec| File signature | `MZ` (hex `4D 5A`) at offset 0 - DOS stub; PE signature (bytes `50 45 00 00`) at the offset given by the 4-byte LE pointer at header offset `0x3C` |
| Base binary format | PE32+ (64-bit Portable Executable) - same container format as a Windows `.exe`, differentiated only by the PE Subsystem field value |
| PE subsystem field values | 10 = EFI Application; 11 = EFI Boot Service Driver; 12 = EFI Runtime Driver; 13 = EFI ROM Image |
| MIME type | `application/efi` |
| Supported CPU architectures | x86-64 (IA-32e), IA-32, ARM Thumb-2, AArch64, RISC-V 32/64/128, IA-64 (Itanium) - architecture encoded in the PE Machine field |
| Required partition and filesystem | EFI System Partition (ESP) formatted as FAT12, FAT16, or FAT32 on a GPT-partitioned disk; NTFS and ext4 are not supported natively by UEFI firmware |
| Standard install path on ESP | `\EFI\<Vendor>\<name>.efi` - e.g., `\EFI\Microsoft\Boot\bootmgfw.efi` or `\EFI\ubuntu\grubx64.efi` |
| Secure Boot code signing | Signed with Authenticode (RSA + SHA-256); verified against UEFI Secure Boot key databases: PK (Platform Key), KEK, `db` (allowed), and `dbx` (revoked) |
| Entry point prototype | `EFI_STATUS EFIAPI ImageEntry(EFI_HANDLE ImageHandle, EFI_SYSTEM_TABLE *SystemTable)` - same signature for all EFI application types |
| Execution privilege level | Highest CPU privilege level - ring 0 (CPL0) on x86; EL1 or EL2 on AArch64 - in a flat pre-OS address space with direct hardware access |
| Boot Service vs. Runtime residency | Boot Service Drivers (subsystem 11) are unloaded when the OS calls `ExitBootServices()`; Runtime Drivers (subsystem 12) remain mapped after OS handoff |
| Disk partitioning requirement | GPT (GUID Partition Table) required for native UEFI boot mode; MBR-only disks are not supported |
| Common well-known binaries | `bootmgfw.efi` (Windows Boot Manager), `grubx64.efi` (GRUB), `shimx64.efi` (Secure Boot shim), `Shell.efi` (UEFI interactive shell) |
| Build toolchains | EDK II (TianoCore), GNU-EFI, LLVM/clang with `-target x86_64-unknown-uefi`; output must be linked as a PE32+ image with UEFI subsystem flags |
| Released | EFI 1.0 (Intel, ~2000) → UEFI 2.x (UEFI Forum, 2005+); standard on PCs since ~2012 |
| Open standard | Yes · royalty-free |
| Specification | uefi.org |
EFI conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about EFI files.