{"id":802326,"date":"2026-07-14T23:34:13","date_gmt":"2026-07-14T23:34:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/802326\/"},"modified":"2026-07-14T23:34:13","modified_gmt":"2026-07-14T23:34:13","slug":"microsofts-secure-boot-has-been-broken-for-a-decade-and-no-one-noticed-until-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/802326\/","title":{"rendered":"Microsoft\u2019s Secure Boot has been broken for a decade and no one noticed until now"},"content":{"rendered":"<p>Further complicating the process, even the expiration of the Microsoft certificate that signed the shims, which took place <a href=\"https:\/\/arstechnica.com\/security\/2026\/06\/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near\/\" rel=\"nofollow noopener\" target=\"_blank\">late last month<\/a>, isn\u2019t enough to revoke the ones ESET identified.<\/p>\n<p>A rogue\u2019s gallery of defective shims<\/p>\n<p>The shims identified by ESET authorize secondary components that are known to be vulnerable to various exploits. The Oracle shim, for instance, signs a binary vulnerable to <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-5281\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2015-5381<\/a>. Smol\u00e1r said the skill required to exploit the vulnerability is low. Other vulnerable shims fail to support protections, such as MOK deny-list enforcement and SBAT enforcement, both of which came into effect after the affected shim was released. Still other identified shims contain vulnerabilities in their own code.<\/p>\n<p>In the interest of brevity, many additional details included in Tuesday\u2019s report are omitted from this article.<\/p>\n<p>An unsettling prospect<\/p>\n<p>As noted, these vulnerable shims can be used against Windows and Linux machines alike, although likely not Windows 11 Secured-core PCs in their default state. Any Windows user who has installed Microsoft\u2019s June update batch is no longer vulnerable. Linux users should check the <a href=\"https:\/\/fwupd.org\" rel=\"nofollow noopener\" target=\"_blank\">Linux Vendor Firmware Service<\/a> or consult their distributor. Revocation statuses are available using the <a href=\"https:\/\/github.com\/sei-vsarvepalli\/uefi-dbx-audit\/\" rel=\"nofollow noopener\" target=\"_blank\">uefi-dbx-audit <\/a> script.<\/p>\n<p>The prospect that attackers have had the means to bypass Secure Boot for more than a decade through what amounts to hack-by-numbers scripts isn\u2019t much of an endorsement of the mechanism proposed by Microsoft in partnership with hardware makers. As mentioned earlier, a key contributor to this debacle is its complexity.<\/p>\n<p>\u201cThis is a solid rebuke of the entire secure boot model,\u201d HD Moore, a firmware security expert, CEO and founder of runZero, and a long-time critic of Secure Boot, said in an interview. His complaints include Microsoft being the de facto root of trust for the entire UEFI platform, the inability of the protection to scale sufficiently, and the ability for components to boot even after top-level certificates expire.<\/p>\n<p>\u201cThe end result is a huge number of unknown (to everyone but Microsoft) signed things that bypass Secure Boot\u2014some of which can then be used to boot other things\u2014and both have normal security bugs and other mistakes that mean they can be used to boot nearly anything,\u201d Moore added. \u201cThe whole ecosystem is somewhat broken and needs a reboot.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Further complicating the process, even the expiration of the Microsoft certificate that signed the shims, which took place&hellip;\n","protected":false},"author":2,"featured_media":802327,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,61],"class_list":["post-802326","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/802326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=802326"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/802326\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/802327"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=802326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=802326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=802326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}