Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

2026-07-15T08:51:44Zf7365f5b40a64d2d2a00339594168efb19f05ec6577185dd8c8756a59b322640
MicrosoftSecure BootSecure Boot bypassUEFIbootloaderendpoint securityfirmwarepatchingpersistencerevocationshimsupply chain

What happened

Researchers reported that Microsoft failed to revoke long‑forgotten UEFI "shim" binaries signed with Microsoft's key, effectively allowing trivial Secure Boot bypasses for years. The unrevoked shims let attackers load unsigned or malicious boot components on systems that rely on Microsoft‑signed bootloaders (commonly affecting Windows and Linux installations that chain to Microsoft's key), enabling persistent boot‑time malware, kernel/DSE bypasses, and supply‑chain or local privilege escalation attacks. Immediate mitigation requires revoking the affected shims, updating Secure Boot DB/DBX keys

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
f7365f5b40a64d2d2a00339594168efb19f05ec6577185dd8c8756a59b322640
Enrichment time
2026-07-15T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.