Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Security researchers at ESET discovered that Microsoft's Secure Boot feature has been vulnerable for a decade due to unrevoked 'shims' used for Linux compatibility. These flaws allow attackers to bypass firmware protections and install persistent malicious software.
Why it matters
This vulnerability exposes millions of Windows and Linux devices to deep-level firmware attacks that persist even after operating system reinstallation.
SECURE BOOT NEEDS A REBOOT Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Old and forgotten “shims” Microsoft failed to revoke have made Secure Boot bypasses simple.
10 Finger about to press a power button. Hardware equipment concept. Credit: Getty Images Finger about to press a power button. Hardware equipment concept. Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in