Skip to main content
See every side of every news story
Published loading...Updated

Microsoft’s Secure Boot Has Been Broken for a Decade and No One Noticed Until Now

ESET said the shims authorize vulnerable components and can let attackers bypass Secure Boot on Windows and Linux systems.

  • Researchers at ESET discovered 11 vulnerable UEFI 'shim' bootloaders dating back to 2013 that remained trusted by Microsoft for years despite known flaws, allowing attackers to bypass Secure Boot on Windows and Linux machines.
  • Secure Boot, introduced in 2012 to prevent boot-chain attacks, relies on Microsoft as the root of trust to sign all code including shims that let non-Microsoft software run; the affected shims came from vendors like Red Hat, openSUSE, and Oracle but were never revoked.
  • The identified shims authorize components with known vulnerabilities, including an Oracle shim vulnerable to CVE-2015-5381 that requires minimal skill to exploit, while others lack critical protections like MOK deny-list and SBAT enforcement developed after their release.
  • Attackers exploiting these shims can load malicious firmware before the operating system starts, potentially persisting through OS reinstalls and hardware changes. Windows users with June updates are protected, though Linux users must verify patches with their distributor.
  • The vulnerability exposes fundamental flaws in Secure Boot's architecture, with HD Moore, CEO and founder of runZero, arguing 'the whole ecosystem is somewhat broken and needs a reboot' due to poorly tracked signed components and Microsoft's unchecked role as UEFI root of trust.
Insights by Ground AI

16 Articles

For more than a decade, Secure Boot could be eliminated in Windows with simple means. Security researchers have found out this out. Why attackers have been able to do this. read more on t3n.de

Security researchers have revealed a major vulnerability affecting Microsoft's Secure Boot system for thirteen years. Designed to protect your PC from malware at startup, Secure Boot could be bypassed by hackers to install malware on Windows and Linux.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Manila Times broke the news in Manila, Philippines (the) on Tuesday, July 14, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal