Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

by | Aug 5, 2026 | Technology

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Security researchers at ESET discovered that Microsoft’s Secure Boot mechanism, an industry-wide standard designed to protect devices from firmware infections, has been trivial to bypass for 13 of its 14 years of existence. The vulnerability stems from Microsoft’s failure to revoke 11 firmware images known as shims that contained known defects, with some dating back to 2013.

Shims are secondary trust anchors that extend Secure Boot to Linux devices and utility software. According to ESET researcher Martin Smolár, circumventing Secure Boot using these old shims requires no novel vulnerabilities or advanced exploitation techniques—only a copy of an old but still-trusted unrevoked shim binary and basic knowledge of how UEFI shims function. Once installed, attackers can subvert the firmware’s digitally signed chain to install malicious firmware that persists even after operating system reinstallation or hard drive replacement.

Secure Boot was introduced in 2012 to protect against bootkits, malicious firmware that can be installed by attackers with brief physical access to devices. The threat affects both Windows and Linux users. Several known bootkits, including LoJax, MosaicRegressor, CosmicStrand, and BlackLotus, have exploited similar vulnerabilities in the past.

Microsoft finally revoked the vulnerable shims in June after ESET reported the issue to CERT and Microsoft. However, the company has not explained how the oversight occurred. The complexity of Secure Boot’s architecture, which uses multiple revocation methods including SBAT and Secure Boot Advanced Targeting, may have contributed to the lapse. The vulnerability also persisted despite the expiration of Microsoft’s certificate that signed the shims earlier.

The discovery has drawn criticism from firmware security experts, including runZero CEO HD Moore, who characterized the incident as “a solid rebuke of the entire secure boot model.” Concerns include Microsoft’s role as the de facto root of trust for the UEFI platform, scalability limitations, and the accumulation of signed components that can bypass security protections. Windows users who installed Microsoft’s June update are no longer vulnerable, while Linux users should verify their systems through the Linux Vendor Firmware Service or their distributor.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI