Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

by | Aug 2, 2026 | Technology

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Security researchers at ESET identified a significant vulnerability in Microsoft’s Secure Boot mechanism after discovering 11 firmware images, known as shims, that had remained signed by the company despite containing known defects. Some of these images dated back to 2013 and were never revoked by Microsoft, despite the company’s responsibility for overseeing their security status.

Shims were originally designed to extend Secure Boot functionality to Linux devices and utility software. The bypass technique requires only basic technical knowledge and access to these old, unrevoked shim binaries. Once installed on a device, attackers can circumvent the digitally signed firmware chain and install malicious code that executes during the boot process. This malware persists even after operating system reinstallation or hard drive replacement, making it particularly dangerous.

Secure Boot was introduced in 2012 as a defense against bootkits—malicious firmware programs that infect devices at the firmware level. Without this protection, attackers with brief physical access to a device can install persistent malware. The vulnerability affects both Windows and Linux users, though Windows 11 Secured-core PCs may be less exposed in their default configuration.

Microsoft finally revoked these vulnerable shims in its monthly patch release in June, after ESET reported the issue to the Computer Emergency Response Team and Microsoft directly. The company has not publicly explained how the revocation oversight occurred over such an extended period. The complexity of Secure Boot’s architecture, which relies on multiple revocation databases and version-based security mechanisms, may have contributed to the administrative failure.

Industry experts have criticized the incident as emblematic of broader architectural weaknesses in Secure Boot. Critics point to the complexity of the system, Microsoft’s role as the de facto root of trust for the entire UEFI platform, and the inability of the mechanism to scale effectively across the diverse ecosystem of firmware components.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI