Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
2026-07-15T08:51:44Z•f7365f5b40a64d2d2a00339594168efb19f05ec6577185dd8c8756a59b322640
MicrosoftSecure BootSecure Boot bypassUEFIbootloaderendpoint securityfirmwarepatchingpersistencerevocationshimsupply chain
What happened
Researchers reported that Microsoft failed to revoke long‑forgotten UEFI "shim" binaries signed with Microsoft's key, effectively allowing trivial Secure Boot bypasses for years. The unrevoked shims let attackers load unsigned or malicious boot components on systems that rely on Microsoft‑signed bootloaders (commonly affecting Windows and Linux installations that chain to Microsoft's key), enabling persistent boot‑time malware, kernel/DSE bypasses, and supply‑chain or local privilege escalation attacks. Immediate mitigation requires revoking the affected shims, updating Secure Boot DB/DBX keys
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- f7365f5b40a64d2d2a00339594168efb19f05ec6577185dd8c8756a59b322640
- Enrichment time
- 2026-07-15T08:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.