tech
Microsoft's Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten “shims” Microsoft failed to revoke have made Secure Boot bypasses simple.

TL;DR
- Microsoft's Secure Boot, designed to prevent firmware infections, has been trivially bypassable for 13 years.
- Researchers found 11 vulnerable firmware images (shims) that were still digitally signed by Microsoft, some dating back to 2013.
- These old shims allow novice hackers to circumvent Secure Boot, a feature embedded in a device's UEFI.
- The bypass is possible because Microsoft failed to revoke the compromised shims, even after vulnerabilities were discovered.
- The threat impacts both Windows and Linux users, as attackers can install persistent malicious firmware.
- Secure Boot was introduced in 2012 to combat bootkits, but this flaw undermines its effectiveness.
- The complexity of Secure Boot's database management (db and dbx) and revocation methods (SBAT, SVN) may have contributed to the oversight.
- Microsoft revoked the vulnerable shims in June after the issue was brought to their attention by ESET.
- While Windows 11 Secured-core PCs and systems updated with Microsoft's June patch are likely protected, older systems and Linux users should verify their status.